CVE-2026-93204
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2026
Last modified:
03/10/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
batman-adv: dat: atomically update mac addresses<br />
<br />
When a MAC address is updated in batadv_dat_entry_add(), it is done using a<br />
simple copy function. A parallel reader might only see parts of this<br />
update. In worst case, the reader is transporting the half updated MAC<br />
address over the network or is creating an ARP response using it -<br />
poisoning the ARP cache.<br />
<br />
atomic64_t can be used to store the 48 bit of a mac address. A reader will<br />
then either see the old mac address or the new one - never a mixture of<br />
both.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/159360a0de831845c4500b4f8638decdcd624040
- https://git.kernel.org/stable/c/1674855a5b6eacfe35f4db3095d7055c25467274
- https://git.kernel.org/stable/c/181012b3d29c51197c235ee5871fc7512c736855
- https://git.kernel.org/stable/c/259db2c04586d40b82c5c3002b1e28b0698a0bb7
- https://git.kernel.org/stable/c/66238e2a74eca5dabf85b0cd2c3c944e474dc2fd
- https://git.kernel.org/stable/c/a5e4d6cb4f6848b8906c1c493f99a8ccc0638515
- https://git.kernel.org/stable/c/e6de568d3eda3e3c01c868fabd7a9535d5ee4a73
- https://git.kernel.org/stable/c/f68038c77a2f38c09c7e2e4f7fa1f4e246fdf2c9


