Junglewise Threat Intelligence

CVE-2026-64093: Linux Kernel batman-adv race condition in tp_meter timer cleanup

CVE-2026-64093 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's batman-adv networking module, which is used for managing mesh networks. A race condition in the throughput meter component could allow a system timer to be improperly restarted after it was supposed to be shut down. This could lead to unpredictable system behavior or memory issues when the system attempts to access data that has already been cleaned up.

Technical details

A race condition exists in net/batman-adv/tp_meter.c within the Linux kernel. The batadv_tp_sender_cleanup() function previously used a non-atomic double-deletion sequence (timer_delete_sync followed by timer_delete) to stop the sender timer. A race condition occurs if batadv_tp_recv_ack() triggers batadv_tp_reset_sender_timer() between these calls; the timer may be re-armed even though the underlying reference is being destroyed. This is resolved by using timer_shutdown_sync(), which permanently disarms the timer and prevents subsequent re-arming. The issue affects the throughput meter (tp_meter) component of the B.A.T.M.A.N. Advanced mesh routing protocol.

Affected products

  • Linux Linux Kernel 33a3bb4a3345 to 00bf4bb9947b

Timeline

  • 2026-05-28: patched: Initial patch authored by Sven Eckelmann
  • 2026-07-19: disclosed: CVE published

References

Related threats