Junglewise Threat Intelligence

CVE-2026-64218: Linux Kernel batman-adv use-after-free in Bridge Loop Avoidance

CVE-2026-64218 · Severity: info · CVSS 5.5 · Published 2026-07-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's batman-adv networking module, which is used for managing mesh networks. The issue occurs when the system attempts to clean up old network gateway entries, potentially leading to a system crash or memory corruption because background tasks might still be trying to access that memory. This could impact the stability and availability of devices using this specific networking protocol.

Technical details

A vulnerability in batadv_bla_purge_backbone_gw() in the batman-adv module of the Linux kernel arises from a race condition during the removal of stale backbone gateway entries. The function failed to properly synchronize with report_work items; if a worker was running or pending during a purge, it could attempt to access memory (such as bat_priv) after it had been freed. The root cause was the invocation of cleanup routines within a spinlock-protected region where sleeping (required for cancel_work_sync) is not permitted. The fix restructures the purging loop to release the spinlock before synchronizing and canceling pending work, ensuring memory is not accessed post-deallocation.

Affected products

  • Linux Linux Kernel 23721387c409 to 0459430add32ea41f3e2ef9351610e6d33627a6b

Timeline

  • 2026-05-10: patched: Initial patch authored by Sven Eckelmann
  • 2026-07-24: disclosed: CVE published in NVD dataset

References

Related threats