CVE-2026-93204

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2026
Last modified:
03/10/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> batman-adv: dat: atomically update mac addresses<br /> <br /> When a MAC address is updated in batadv_dat_entry_add(), it is done using a<br /> simple copy function. A parallel reader might only see parts of this<br /> update. In worst case, the reader is transporting the half updated MAC<br /> address over the network or is creating an ARP response using it -<br /> poisoning the ARP cache.<br /> <br /> atomic64_t can be used to store the 48 bit of a mac address. A reader will<br /> then either see the old mac address or the new one - never a mixture of<br /> both.

Impact