CVE-2026-64093
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
11/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
batman-adv: tp_meter: directly shut down timer on cleanup<br />
<br />
batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by<br />
timer_delete() to guard against the timer handler re-arming itself between<br />
the two calls. This double-deletion hack relied on the sending status being<br />
set to 0 to suppress re-arming.<br />
<br />
Replace both calls with a single timer_shutdown_sync(). This function both<br />
waits for any running timer callback to complete (like timer_delete_sync())<br />
and permanently disarms the timer so it cannot be re-armed afterwards,<br />
making re-arming prevention unconditional and self-documenting.<br />
<br />
The re-arming property is also required because otherwise:<br />
<br />
1. context 0 (batadv_tp_recv_ack()) checks in<br />
batadv_tp_reset_sender_timer() if sending is still 1 -> it is<br />
2. context 1 changes in batadv_tp_sender_shutdown() sending to 0 and in<br />
this process forces the kthread to stop timer in<br />
batadv_tp_sender_cleanup()<br />
3. context 0 continues in batadv_tp_reset_sender_timer() and rearms the<br />
timer -> but the reference for it is already gone
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.8 (including) | 5.15.210 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.176 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.93 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.34 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/00bf4bb9947b1190a8be8d9b6a1bcbfa3707785c
- https://git.kernel.org/stable/c/5bc2d50fb66b46f86543d5153a188eb1486d0b6e
- https://git.kernel.org/stable/c/74a76634055462833446684fd526d73c290ea43a
- https://git.kernel.org/stable/c/770bf0a35f0620b526fd4193889d1e77084e4c43
- https://git.kernel.org/stable/c/933880a8bc9b4042223a79255c0b1021cdc36991
- https://git.kernel.org/stable/c/d5487249a81ea658717614009c8f46acc5b7101a
- https://git.kernel.org/stable/c/f86b20ec8d17d77bddc02c5c86cfa2389d84ecff



