CVE-2026-64093 Details
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming itself between the two calls. This double-deletion hack relied on the sending status being set to 0 to suppress re-arming. Replace both calls with a single timer_shutdown_sync(). This function both waits for any running timer callback to complete (like timer_delete_sync()) and permanently disarms the timer so it cannot be re-armed afterwards, making re-arming prevention unconditional and self-documenting. The re-arming property is also required because otherwise: 1. context 0 (batadv_tp_recv_ack()) checks in batadv_tp_reset_sender_timer() if sending is still 1 -> it is 2. context 1 changes in batadv_tp_sender_shutdown() sending to 0 and in this process forces the kthread to stop timer in batadv_tp_sender_cleanup() 3. context 0 continues in batadv_tp_reset_sender_timer() and rearms the timer -> but the reference for it is already gone
A vulnerability in the Linux kernel's batman-adv module has been addressed, specifically within the throughput meter implementation. The issue arose in the timer management during the cleanup process of the sender variables. Previously, the cleanup function relied on a double deletion method to prevent the timer handler from re-arming itself, which could lead to a reference loss. This workaround depended on the sending status being manually reset. The vulnerability has been fixed by replacing the two deletion calls with a single, more effective command that safely shuts down the timer, ensuring it cannot be re-armed, thus eliminating the risk of improper timer management.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability. Instructions for downloading the patched version can be found in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/00bf4bb9947b1190a8be8d9b6a1bcbfa3707785c | kernel.org | Patch |
| https://git.kernel.org/stable/c/5bc2d50fb66b46f86543d5153a188eb1486d0b6e | kernel.org | Patch |
| https://git.kernel.org/stable/c/74a76634055462833446684fd526d73c290ea43a | kernel.org | Patch |
| https://git.kernel.org/stable/c/770bf0a35f0620b526fd4193889d1e77084e4c43 | kernel.org | Patch |
| https://git.kernel.org/stable/c/933880a8bc9b4042223a79255c0b1021cdc36991 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d5487249a81ea658717614009c8f46acc5b7101a | kernel.org | Patch |
| https://git.kernel.org/stable/c/f86b20ec8d17d77bddc02c5c86cfa2389d84ecff | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.8, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.93 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |