Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64093

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> batman-adv: tp_meter: directly shut down timer on cleanup<br /> <br /> batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by<br /> timer_delete() to guard against the timer handler re-arming itself between<br /> the two calls. This double-deletion hack relied on the sending status being<br /> set to 0 to suppress re-arming.<br /> <br /> Replace both calls with a single timer_shutdown_sync(). This function both<br /> waits for any running timer callback to complete (like timer_delete_sync())<br /> and permanently disarms the timer so it cannot be re-armed afterwards,<br /> making re-arming prevention unconditional and self-documenting.<br /> <br /> The re-arming property is also required because otherwise:<br /> <br /> 1. context 0 (batadv_tp_recv_ack()) checks in<br /> batadv_tp_reset_sender_timer() if sending is still 1 -&gt; it is<br /> 2. context 1 changes in batadv_tp_sender_shutdown() sending to 0 and in<br /> this process forces the kthread to stop timer in<br /> batadv_tp_sender_cleanup()<br /> 3. context 0 continues in batadv_tp_reset_sender_timer() and rearms the<br /> timer -&gt; but the reference for it is already gone