CVE-2026-64089 Details
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_my_tt_response(), last_changeset_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but populates only a small portion of it with the collected changeset. All remaining bits are kept uninitialized. Using an u16 avoids this type confusion and ensures that no (negative) sign extension is performed in batadv_send_my_tt_response().
A vulnerability in the Linux kernel's batman-adv module has been addressed. The issue arose because the 'last_changeset_len' field was declared as a signed 16-bit integer, which could incorrectly hold negative values. When a value exceeding 32767 was assigned, it wrapped around to a negative integer. This negative value was then propagated into a 32-bit integer, leading to a buffer allocation that was larger than necessary. The excess buffer space remained uninitialized, creating a potential risk. The vulnerability has been fixed by changing the data type of 'last_changeset_len' to an unsigned 16-bit integer, preventing negative values and ensuring proper data handling.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/179eb62506a02d00370bd6478898cb632e10986c | kernel.org | Patch |
| https://git.kernel.org/stable/c/22d59c72f4a47ffec121d0610f70d0d70c3c11c8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/55dc41fe8821e9a849e147255ad572bc933a9d15 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6314089acf0ddf64376fdc0b1420695504c73f52 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c424e8519ac78eac5d9f4eecf06208a0d619ec14 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d29abf70c665730e249d2ec8e1402095ae26bcee | kernel.org | Patch |
| https://git.kernel.org/stable/c/eb235472b52ef36981c5aad330485eaf2382c53b | kernel.org | Patch |
| https://git.kernel.org/stable/c/fc92cdfcb295cefa4344d71a527d61b638b7bfc4 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.1, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |