CVE-2026-46233 Details
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims When batadv_bla_purge_claims() goes through the list of claims, it is only traversing the hash list with an rcu_read_lock(). Due to a potential parallel batadv_claim_put(), it can happen that it encounters a claim which was actually in the process of being released+freed by batadv_claim_release(). In this case, backbone_gw is set to NULL before the delayed RCU kfree is started. Calling batadv_bla_claim_get_backbone_gw() is then no longer allowed because it would cause a NULL-ptr derefence. To avoid this, only claims with a valid reference counter must be purged. All others are already taken care of.
A vulnerability in the Linux kernel's batman-adv module can cause a NULL pointer dereference. This issue arises in the claim purging function, batadv_bla_purge_claims(), which improperly handles claims that are in the process of being released. The function only traverses the claim list with a read lock, allowing it to encounter claims that have been partially freed. As a result, the backbone_gw pointer can be set to NULL before the claim is fully released, leading to a dereference of a NULL pointer when the backbone_gw is accessed. The vulnerability affects the Linux kernel stable tree.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. The specific commit that resolves this issue is available in the Linux stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/6725c523a35eeca611ff37e7d4a8712fae92aefd | kernel.org | Patch |
| https://git.kernel.org/stable/c/7b7ebb7222a5524ce58e48cc9c6d688320ea6cfe | kernel.org | Patch |
| https://git.kernel.org/stable/c/7b8fbcee3184d848b5aee085ca16d0cf05c9b641 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a9f58d5e3261f3deeae69ec1e237f38ef3ff5cbe | kernel.org | Patch |
| https://git.kernel.org/stable/c/ab3dbd07a809a8eb30c7ddfab9ac886ed30dce8d | kernel.org | Patch |
| https://git.kernel.org/stable/c/afb5436f6028fd68f408f189230fbaa19c910d72 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b65365d2b1e6095c538d49baeb140dd1c166c1b3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cf6b604011591865ae39ac82de8978c1120d17af | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.5, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.90 >= 6.13, < 6.18.32 >= 6.19, < 7.0.9 7.1 rc1 7.1 rc2 7.1 rc3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 10, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |