Junglewise Threat Intelligence

CVE-2026-64096: Linux kernel use-after-free in batman-adv mcast purge

CVE-2026-64096 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's batman-adv mesh networking module. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized actions due to improper memory management during network node cleanup. The issue specifically affects systems using the B.A.T.M.A.N. Advanced protocol for wireless mesh networking.

Technical details

A use-after-free vulnerability exists in net/batman-adv/originator.c within the Linux kernel. The function batadv_mcast_purge_orig() removes entries from RCU-protected hlists without waiting for an RCU grace period. Consequently, concurrent RCU readers may attempt to access references to these entries, such as mcast_want_all_ipv6_node, after the memory has been reclaimed. The fix involves moving the purge call to batadv_orig_node_release() before the call_rcu() invocation to ensure all readers have drained. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux kernel 3.15 to 5.10.258

Timeline

  • 2026-07-19: advisory: CVE-2026-64096 published by NVD
  • 2026-05-14: patched: Initial fix authored by Sven Eckelmann

References

Related threats