CVE-2026-64092
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
The receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is responsible for releasing the tp_vars reference it holds. However, the existing logic for coordinating this release with batadv_tp_stop_all() was flawed.
timer_shutdown_sync() guarantees the timer will not fire again after it returns, but it returns non-zero only when the timer was pending at the time of the call. If the timer had already expired (and batadv_tp_stop_all() would unsucessfully try to rearm itself), batadv_tp_stop_all() skips its batadv_tp_vars_put(), and batadv_tp_receiver_shutdown() fails to put its own reference as well.
Fix this by introducing a new atomic variable receiving that is set to 1 when the receiver is initialized and cleared atomically with atomic_xchg() by whichever side claims it first. Only the side that observes the transition from 1 to 0 is responsible for releasing the tp_vars timer reference, eliminating the uncertainty.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 268078acae72daa12b17b2b299701cb9924e469a < 7715c73f33260af724d734c41b794457e9be8dbc | affected |
| Linux | Linux | 58943b7ea356294749dae3e75b96c0ee292c00be < 297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae | affected |
| Linux | Linux | 79bc0eaeef2c5797317bf2da8e3159a74d62ec47 < 0b1bedf114ea93fef929b31f0d70a9eedcc601de | affected |
| Linux | Linux | 26dfeee8db81354bfdade155f27f9e16510ad196 < a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0 | affected |
| Linux | Linux | 03660dab86f93319178a24667f6998526dc4355d < b285bc0a97f43823a4967fb6d286de4c7f53d541 | affected |
| Linux | Linux | 8634c1dbd73adb74d40533ebb7e914efb82e71fb < d078501dde9b57210f1808cdef4b59463d1f5fc8 | affected |
| Linux | Linux | 3d3cf6a7314aca4df0a6dde28ce784a2a30d0166 < 77098e4bea37af51d3962efa88a5af2ea5e1ac57 | affected |
| Linux | Linux | 5e7d0ac936354c36810e74ac3056b334ed1f4058 | affected |
| Linux | Linux | 5.10.259 < 5.11 | affected |
| Linux | Linux | 6.6.140 < 6.6.142 | affected |
| Linux | Linux | 6.12.90 < 6.12.92 | affected |
| Linux | Linux | 6.18.32 < 6.18.34 | affected |
| Linux | Linux | 7.0.9 < 7.0.11 | affected |
Weaknesses
References
- https://git.kernel.org/stable/c/7715c73f33260af724d734c41b794457e9be8dbc
- https://git.kernel.org/stable/c/297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae
- https://git.kernel.org/stable/c/0b1bedf114ea93fef929b31f0d70a9eedcc601de
- https://git.kernel.org/stable/c/a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0
- https://git.kernel.org/stable/c/b285bc0a97f43823a4967fb6d286de4c7f53d541
- https://git.kernel.org/stable/c/d078501dde9b57210f1808cdef4b59463d1f5fc8
- https://git.kernel.org/stable/c/77098e4bea37af51d3962efa88a5af2ea5e1ac57
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.