batman-adv: bla: fix freeing of claims on meshif deletion
Summary
| CVE | CVE-2026-89948 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 11:17:04 UTC |
| Updated | 2026-09-16 11:17:04 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
batman-adv: bla: fix freeing of claims on meshif deletion
When the mesh interface is getting deleted, then
batadv_bla_del_backbone_claims() (via batadv_bla_purge_backbone_gw()) could
make sure that all claims gets removed. But this function is only executed
when bat_priv->bla.claim_hash is not NULL. And since batadv_bla_free() is
always setting it to NULL before it is (indirectly) called, it was never
actually executed.
But the batadv_bla_purge_claims() -> batadv_handle_unclaim() is at the
moment too fragile because the BLA code is not handling the rehashing in
batadv_bla_update_orig_address(). The stored backbone address doesn't have
to be the one actually used for the hash bucket selection during the
initial adding of the backbone. The batadv_handle_unclaim() can therefore
fail to find the respective backbone for the unclaim and then stop the
deletion.
But the actual backbone_gw object is not needed for the unclaim because all
relevant information is always provided by the caller. And the check for
the existence of the backbone_gw doesn't provide any additional security
check for the deletion of a claim. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 844a95a734f178d56c7acce14c5cce2cecff7e1a git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 baeb1a28fd8e2f68193650d3664a8cd1adfd85c6 git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 aacffa780a37e06cd5a13d33740a6e96c3a67e6c git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 76aedcde5a2489cc971d4d1e396e784a49565e96 git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 f50edb69082a8ba990cc23d642089829f99afe6a git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 871acdf97f64cee8398f72b88b89e8b4f4816dbe git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 9a0c47023d3254048a1588534755d4476bcc3abc git |
Not specified |
| CNA |
Linux |
Linux |
affected 23721387c409087fd3b97e274f34d3ddc0970b74 8d128c932bced74e3b1625ba3d7c78ef122a88a7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.5 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.5 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.270 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.51 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.5 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/9a0c47023d3254048a1588534755d4476bcc3abc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/baeb1a28fd8e2f68193650d3664a8cd1adfd85c6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8d128c932bced74e3b1625ba3d7c78ef122a88a7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/844a95a734f178d56c7acce14c5cce2cecff7e1a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/871acdf97f64cee8398f72b88b89e8b4f4816dbe |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f50edb69082a8ba990cc23d642089829f99afe6a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/aacffa780a37e06cd5a13d33740a6e96c3a67e6c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/76aedcde5a2489cc971d4d1e396e784a49565e96 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.