Executive brief
A vulnerability was identified in the Linux kernel's B.A.T.M.A.N. Advanced mesh networking protocol. A flaw in how the system shuts down certain network measurement tools can lead to a memory leak. Over time, this could potentially degrade system performance or lead to instability in environments using mesh networking.
Technical details
A reference leak exists in net/batman-adv/tp_meter.c due to flawed coordination between batadv_tp_receiver_shutdown() and batadv_tp_stop_all(). The issue stems from reliance on timer_shutdown_sync(), which only returns non-zero if a timer was pending; if the timer had already expired but the reference was not yet put, both functions could skip the required batadv_tp_vars_put() call. This results in a tp_vars reference leak. The fix introduces an atomic 'receiving' variable to ensure exactly one execution path responsible for the final reference release. Patching is available in various stable kernel branches.
Affected products
- Linux Linux Kernel 5.10.259 to 5.11; 6.x; 7.x
Timeline
- 2026-05-10: disclosed: Initial patch authored by Sven Eckelmann
- 2026-07-19: advisory: CVE-2026-64092 published
References
- https://git.kernel.org/stable/c/0b1bedf114ea93fef929b31f0d70a9eedcc601de
- https://git.kernel.org/stable/c/297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae
- https://git.kernel.org/stable/c/77098e4bea37af51d3962efa88a5af2ea5e1ac57
- https://git.kernel.org/stable/c/7715c73f33260af724d734c41b794457e9be8dbc
- https://git.kernel.org/stable/c/a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0
- https://git.kernel.org/stable/c/b285bc0a97f43823a4967fb6d286de4c7f53d541
- https://git.kernel.org/stable/c/d078501dde9b57210f1808cdef4b59463d1f5fc8