Junglewise Threat Intelligence

CVE-2026-64095: Linux Kernel race condition in batman-adv Bridge Loop Avoidance

CVE-2026-64095 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's B.A.T.M.A.N. Advanced (batman-adv) routing protocol, specifically within its Bridge Loop Avoidance (BLA) component. This component is responsible for preventing network loops in mesh environments. An exploit could lead to incorrect internal state tracking, potentially causing network instability or unexpected behavior in how the mesh handles traffic across different network segments.

Technical details

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the Bridge Loop Avoidance (BLA) implementation of the batman-adv module. The root cause is the non-atomic handling of the 'request_sent' state and the 'bla.num_requests' counter across multiple concurrent code paths (announcement handling, backbone purging, and periodic work). An attacker or specific network conditions could trigger a race where 'num_requests' is decremented twice or modified inconsistently, leading to an incorrect count of pending requests. The fix introduces a spinlock (num_requests_lock) and a new 'stopped' state to ensure atomic transitions and safe cleanup of backbone gateway references.

Affected products

  • Linux Linux Kernel 23721387c409 to 1f013bc94154f2e78e97d0296175664224c796e0

Timeline

  • 2026-05-29: other: Patch authored by Sven Eckelmann
  • 2026-07-19: disclosed: CVE published

References

Related threats