Back to overview

CVE-2026-64092

Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown The receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is responsible for releasing the tp_vars reference it holds. However, the existing logic for coordinating this release with batadv_tp_stop_all() was flawed. timer_shutdown_sync() guarantees the timer will not fire again after it returns, but it returns non-zero only when the timer was pending at the time of the call. If the timer had already expired (and batadv_tp_stop_all() would unsucessfully try to rearm itself), batadv_tp_stop_all() skips its batadv_tp_vars_put(), and batadv_tp_receiver_shutdown() fails to put its own reference as well. Fix this by introducing a new atomic variable receiving that is set to 1 when the receiver is initialized and cleared atomically with atomic_xchg() by whichever side claims it first. Only the side that observes the transition from 1 to 0 is responsible for releasing the tp_vars timer reference, eliminating the uncertainty.

Metadata

CVE ID
CVE-2026-64092
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:40 UTC
Last updated
2026-07-19 15:40 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 268078acae72daa12b17b2b299701cb9924e469a < 7715c73f33260af724d734c41b794457e9be8dbc, 58943b7ea356294749dae3e75b96c0ee292c00be < 297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae, 79bc0eaeef2c5797317bf2da8e3159a74d62ec47 < 0b1bedf114ea93fef929b31f0d70a9eedcc601de, 26dfeee8db81354bfdade155f27f9e16510ad196 < a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0 …
Linux Linux 6.6.140 < 6.6.142, 6.12.90 < 6.12.92, 6.18.32 < 6.18.34, 7.0.9 < 7.0.11
Back to overview