{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46238","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.107Z","datePublished":"2026-05-28T09:41:06.816Z","dateUpdated":"2026-08-05T12:30:39.402Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:30:39.402Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: stop caching unowned originator pointers in BAT IV\n\nBAT IV keeps the last-hop neighbor address in each neigh_node, but some\npaths also cache an originator pointer derived from a temporary lookup.\nThat pointer is not owned by the neigh_node and may no longer refer to a\nlive originator entry after purge handling runs.\n\nStop storing the auxiliary originator pointer in the BAT IV neighbor\nstate. When BAT IV needs the neighbor originator data, resolve it from\nthe stored neighbor address and drop the reference again after use.\n\n[sven: avoid bonding logic for outgoing OGM]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - batman-adv OGMs are raw layer-2 broadcast management frames (ethertype 0x4305) confined to the mesh segment; the attacker must be on the same WiFi/ad-hoc or wired link-layer mesh as the victim, matching the Adjacent vector for mesh/WiFi frame injection.\nAC:L - The attacker controls all OGM traffic and can deterministically set up the freed-originator condition (purge timeout is fixed and purge work runs every second) before triggering the dereference, so no uncontrollable race is involved.\nPR:N - batman-adv OGM/management packets are unauthenticated with no privilege check; any node able to put frames on the mesh segment can inject them.\nUI:N - No victim interaction is required — the vulnerable BAT IV OGM processing runs automatically on any node running batman-adv with the default routing algorithm.\nS:U - The use-after-free is contained within the kernel's own memory/security context with no crossing of a trust or virtualization boundary.\nC:H - The UAF dereferences a freed originator object that can be reallocated with attacker-controlled heap content, enabling kernel memory disclosure.\nI:H - The stale pointer is used for spinlock acquisition and field access on freed memory; UAF of a heap object enables heap grooming toward an arbitrary write / control-flow primitive.\nA:H - Dereferencing the freed/dangling originator pointer reliably causes a kernel oops/panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/batman-adv/bat_iv_ogm.c"],"versions":[{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"86b2b58d7c228d850c8c78e4144e6123e8ed2718","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"384e3050a42be9085d50507b4d5f8266a588d742","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"8c16c68fdbb69778f8d04f650340c3f4d1518f8e","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"aafcbaf1159ea224528ca4075d0ba8c10ef374af","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"6e20700f8c524ac379ba8274ff5d453023b7c006","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"09dc0d1a12222ffca6481916eab3cfea477b9620","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"67bceeb22207f1f5a402973a3a0809e5f2698f38","status":"affected","versionType":"git"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"f03e8583532941b07761c5429de7d50766fa3110","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/batman-adv/bat_iv_ogm.c"],"versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","status":"unaffected","versionType":"semver"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.90","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.32","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.9","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.10.258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.15.209"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.6.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.12.90"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.18.32"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.0.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/86b2b58d7c228d850c8c78e4144e6123e8ed2718"},{"url":"https://git.kernel.org/stable/c/384e3050a42be9085d50507b4d5f8266a588d742"},{"url":"https://git.kernel.org/stable/c/8c16c68fdbb69778f8d04f650340c3f4d1518f8e"},{"url":"https://git.kernel.org/stable/c/aafcbaf1159ea224528ca4075d0ba8c10ef374af"},{"url":"https://git.kernel.org/stable/c/6e20700f8c524ac379ba8274ff5d453023b7c006"},{"url":"https://git.kernel.org/stable/c/09dc0d1a12222ffca6481916eab3cfea477b9620"},{"url":"https://git.kernel.org/stable/c/67bceeb22207f1f5a402973a3a0809e5f2698f38"},{"url":"https://git.kernel.org/stable/c/f03e8583532941b07761c5429de7d50766fa3110"}],"title":"batman-adv: stop caching unowned originator pointers in BAT IV","x_generator":{"engine":"bippy-1.2.0"}}}}