CVE-2026-46208

Updated on 28 May 2026

Severity

7.8 High severity

Details

CVSS score
7.8

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop tp_meter sessions during mesh teardown TP meter sessions remain linked on bat_priv->tp_list after the netlink request has already finished. When the mesh interface is removed, batadv_mesh_free() currently tears down the mesh without first draining these sessions. A running sender thread or a late incoming tp_meter packet can then keep processing against a mesh instance which is already shutting down. Synchronize tp_meter with the mesh lifetime by stopping all active sessions from batadv_mesh_free() and waiting for sender threads to exit before teardown continues. A flaw was found in the Linux kernel’s batman-adv module. When a mesh interface is removed, the batadv_mesh_free() function does not properly stop tp_meter sessions. This oversight allows active tp_meter sender threads or late incoming packets to continue processing against a mesh instance that is in the process of shutting down. This can lead to system instability and a denial of service (DoS).

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 11 Planned
Debian 11 cloud Planned
Debian 12 Planned
Debian 13 Planned
Ubuntu 24.04 Planned