CVE-2026-64092 Details
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown The receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is responsible for releasing the tp_vars reference it holds. However, the existing logic for coordinating this release with batadv_tp_stop_all() was flawed. timer_shutdown_sync() guarantees the timer will not fire again after it returns, but it returns non-zero only when the timer was pending at the time of the call. If the timer had already expired (and batadv_tp_stop_all() would unsucessfully try to rearm itself), batadv_tp_stop_all() skips its batadv_tp_vars_put(), and batadv_tp_receiver_shutdown() fails to put its own reference as well. Fix this by introducing a new atomic variable receiving that is set to 1 when the receiver is initialized and cleared atomically with atomic_xchg() by whichever side claims it first. Only the side that observes the transition from 1 to 0 is responsible for releasing the tp_vars timer reference, eliminating the uncertainty.
A vulnerability in the Linux kernel's batman-adv module has been addressed, specifically related to a reference leak in the tp_meter functionality during the receiver shutdown process. The issue arose because the receiver shutdown timer handler, batadv_tp_receiver_shutdown(), failed to properly release the tp_vars reference it maintained. This flaw was due to an incorrect synchronization between releasing the reference and stopping all tp_meter sessions, which could lead to a situation where the reference was not properly managed, especially if the shutdown timer had already expired.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0b1bedf114ea93fef929b31f0d70a9eedcc601de | kernel.org | Patch |
| https://git.kernel.org/stable/c/297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae | kernel.org | Patch |
| https://git.kernel.org/stable/c/77098e4bea37af51d3962efa88a5af2ea5e1ac57 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7715c73f33260af724d734c41b794457e9be8dbc | kernel.org | Patch |
| https://git.kernel.org/stable/c/a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b285bc0a97f43823a4967fb6d286de4c7f53d541 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d078501dde9b57210f1808cdef4b59463d1f5fc8 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.10.259, < 5.11 >= 6.6.140, < 6.6.142 >= 6.12.90, < 6.12.92 >= 6.18.32, < 6.18.34 >= 7.0.9, < 7.0.11 7.1 rc4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 19, 2026 | New CVE Received | kernel.org |