batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
Summary
| CVE | CVE-2026-64092 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:50 UTC |
| Updated | 2026-07-19 16:17:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown The receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is responsible for releasing the tp_vars reference it holds. However, the existing logic for coordinating this release with batadv_tp_stop_all() was flawed. timer_shutdown_sync() guarantees the timer will not fire again after it returns, but it returns non-zero only when the timer was pending at the time of the call. If the timer had already expired (and batadv_tp_stop_all() would unsucessfully try to rearm itself), batadv_tp_stop_all() skips its batadv_tp_vars_put(), and batadv_tp_receiver_shutdown() fails to put its own reference as well. Fix this by introducing a new atomic variable receiving that is set to 1 when the receiver is initialized and cleared atomically with atomic_xchg() by whichever side claims it first. Only the side that observes the transition from 1 to 0 is responsible for releasing the tp_vars timer reference, eliminating the uncertainty. |
Risk And Classification
EPSS: 0.001800000 probability, percentile 0.078040000 (date 2026-07-20)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 268078acae72daa12b17b2b299701cb9924e469a 7715c73f33260af724d734c41b794457e9be8dbc git | Not specified |
| CNA | Linux | Linux | affected 58943b7ea356294749dae3e75b96c0ee292c00be 297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae git | Not specified |
| CNA | Linux | Linux | affected 79bc0eaeef2c5797317bf2da8e3159a74d62ec47 0b1bedf114ea93fef929b31f0d70a9eedcc601de git | Not specified |
| CNA | Linux | Linux | affected 26dfeee8db81354bfdade155f27f9e16510ad196 a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0 git | Not specified |
| CNA | Linux | Linux | affected 03660dab86f93319178a24667f6998526dc4355d b285bc0a97f43823a4967fb6d286de4c7f53d541 git | Not specified |
| CNA | Linux | Linux | affected 8634c1dbd73adb74d40533ebb7e914efb82e71fb d078501dde9b57210f1808cdef4b59463d1f5fc8 git | Not specified |
| CNA | Linux | Linux | affected 3d3cf6a7314aca4df0a6dde28ce784a2a30d0166 77098e4bea37af51d3962efa88a5af2ea5e1ac57 git | Not specified |
| CNA | Linux | Linux | affected 5e7d0ac936354c36810e74ac3056b334ed1f4058 git | Not specified |
| CNA | Linux | Linux | affected 5.10.259 5.11 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.140 6.6.142 semver | Not specified |
| CNA | Linux | Linux | affected 6.12.90 6.12.92 semver | Not specified |
| CNA | Linux | Linux | affected 6.18.32 6.18.34 semver | Not specified |
| CNA | Linux | Linux | affected 7.0.9 7.0.11 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/d078501dde9b57210f1808cdef4b59463d1f5fc8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0b1bedf114ea93fef929b31f0d70a9eedcc601de | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b285bc0a97f43823a4967fb6d286de4c7f53d541 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/77098e4bea37af51d3962efa88a5af2ea5e1ac57 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7715c73f33260af724d734c41b794457e9be8dbc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.