{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64093","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.032Z","datePublished":"2026-07-19T15:40:01.172Z","dateUpdated":"2026-08-05T12:39:08.305Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:39:08.305Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: directly shut down timer on cleanup\n\nbatadv_tp_sender_cleanup() was calling timer_delete_sync() followed by\ntimer_delete() to guard against the timer handler re-arming itself between\nthe two calls. This double-deletion hack relied on the sending status being\nset to 0 to suppress re-arming.\n\nReplace both calls with a single timer_shutdown_sync(). This function both\nwaits for any running timer callback to complete (like timer_delete_sync())\nand permanently disarms the timer so it cannot be re-armed afterwards,\nmaking re-arming prevention unconditional and self-documenting.\n\nThe re-arming property is also required because otherwise:\n\n1. context 0 (batadv_tp_recv_ack()) checks in\n   batadv_tp_reset_sender_timer() if sending is still 1 -> it is\n2. context 1 changes in batadv_tp_sender_shutdown() sending to 0 and in\n   this process forces the kthread to stop timer in\n   batadv_tp_sender_cleanup()\n3. context 0 continues in batadv_tp_reset_sender_timer() and rearms the\n   timer -> but the reference for it is already gone"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The bug is triggered in batadv_tp_recv_ack() when forged or legitimate BATADV_TP_ACK mesh packets are received on a batman-adv hard interface; exploitation requires membership on the same batman-adv mesh (shared WiFi/ethernet logical network), which is Adjacent under CVSS and kernel WiFi guidance.\nAC:L - This is a race between batadv_tp_recv_ack()/batadv_tp_reset_sender_timer() and batadv_tp_sender_cleanup(); an adjacent mesh attacker controls ACK timing and can flood packets to reliably hit the window between timer_delete_sync() and timer_delete() while the session tears down.\nPR:N - The vulnerable receive path has no capability or authentication checks; any mesh peer can send TP ACK packets matching an active session without CAP_NET_ADMIN or other privileges on the victim (session start via netlink is a victim-side precondition, not attacker privilege).\nUI:N - Exploitation requires only attacker-timed mesh packets during session teardown; no victim end-user action (opening files, clicking links, etc.) is needed beyond normal mesh operation.\nS:U - Impact is a kernel heap use-after-free in batman-adv with potential privilege escalation; it does not cross a VM, container, or IOMMU security boundary.\nC:H - Re-arming mod_timer() on a freed batadv_tp_vars after batadv_tp_vars_put() is a classic use-after-free; the attacker can influence freed heap contents and obtain arbitrary kernel memory read primitives.\nI:H - The UAF corrupts timer_list and adjacent kmalloc object fields; combined with heap grooming this enables arbitrary kernel writes and control-flow hijacking, not merely a bounded modification.\nA:H - When the re-armed timer fires on freed memory, batadv_tp_sender_timeout() dereferences stale tp_vars pointers, causing kernel oops/panic and reliable remote denial of service even without full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/batman-adv/tp_meter.c"],"versions":[{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"00bf4bb9947b1190a8be8d9b6a1bcbfa3707785c","status":"affected","versionType":"git"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"74a76634055462833446684fd526d73c290ea43a","status":"affected","versionType":"git"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"5bc2d50fb66b46f86543d5153a188eb1486d0b6e","status":"affected","versionType":"git"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"f86b20ec8d17d77bddc02c5c86cfa2389d84ecff","status":"affected","versionType":"git"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"770bf0a35f0620b526fd4193889d1e77084e4c43","status":"affected","versionType":"git"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"933880a8bc9b4042223a79255c0b1021cdc36991","status":"affected","versionType":"git"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"d5487249a81ea658717614009c8f46acc5b7101a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/batman-adv/tp_meter.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/00bf4bb9947b1190a8be8d9b6a1bcbfa3707785c"},{"url":"https://git.kernel.org/stable/c/74a76634055462833446684fd526d73c290ea43a"},{"url":"https://git.kernel.org/stable/c/5bc2d50fb66b46f86543d5153a188eb1486d0b6e"},{"url":"https://git.kernel.org/stable/c/f86b20ec8d17d77bddc02c5c86cfa2389d84ecff"},{"url":"https://git.kernel.org/stable/c/770bf0a35f0620b526fd4193889d1e77084e4c43"},{"url":"https://git.kernel.org/stable/c/933880a8bc9b4042223a79255c0b1021cdc36991"},{"url":"https://git.kernel.org/stable/c/d5487249a81ea658717614009c8f46acc5b7101a"}],"title":"batman-adv: tp_meter: directly shut down timer on cleanup","x_generator":{"engine":"bippy-1.2.0"}}}}