Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: reject new tp_meter sessions during teardown

Prevent tp_meter from starting new sender or receiver sessions after
mesh_state has left BATADV_MESH_ACTIVE.
Published: 2026-05-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The batman‑adv component in the Linux kernel contains a logic oversight that permits the tp_meter subsystem to initiate new sender or receiver sessions even after the mesh network has transitioned out of the BATADV_MESH_ACTIVE state, which can result in inaccurate telemetry data or resource exhaustion, effectively causing a denial of service to measurement functionalities. This flaw is a resource management error (CWE-372) and is further marked as NVD-CWE-noinfo, indicating that no additional specific coding deficiency has been identified beyond the resource exhaustion category. No exploit details or impact beyond telemetry service disruption are described in the advisory.

Affected Systems

The vulnerability appears in any kernel version that incorporates the batman‑adv code before the commits referenced in the advisory were applied. Specific affected releases are not enumerated, but the issue applies to all systems running the unpatched batch of batman‑adv modules. The change is only relevant for deployments that enable the tp_meter feature within a mesh network.

Risk and Exploitability

The advisory lists no publicly available exploitation code, and the EPSS score of < 1% indicates a very low probability of exploitation, while the CVSS score of 7.8 indicates a high severity, and the flaw is not catalogued in CISA’s KEV. The advisory does not state any required privileges; therefore, the extent to which a non-privileged user could trigger the flaw remains unclear. Overall, the risk is considered low for environments that do not expose batman-adv to external interfaces or rely on tp_meter telemetry.

Generated by OpenCVE AI on June 10, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the batman-adv fixes referenced in the advisory.
  • If a kernel upgrade cannot be applied immediately, temporarily disable the tp_meter capability in the batman‑adv configuration or reload the module after the network returns to the BATADV_MESH_ACTIVE state.
  • Continuously monitor kernel logs for tp_meter session creation attempts following a state transition to confirm the mitigation is effective.

Generated by OpenCVE AI on June 10, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*

Mon, 01 Jun 2026 17:00:00 +0000


Sat, 30 May 2026 11:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 29 May 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703

Fri, 29 May 2026 00:15:00 +0000


Thu, 28 May 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703

Thu, 28 May 2026 10:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject new tp_meter sessions during teardown Prevent tp_meter from starting new sender or receiver sessions after mesh_state has left BATADV_MESH_ACTIVE.
Title batman-adv: reject new tp_meter sessions during teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-06-14T18:02:39.871Z

Reserved: 2026-05-13T15:03:33.105Z

Link: CVE-2026-46206

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T10:16:36.243

Modified: 2026-06-10T19:18:18.780

Link: CVE-2026-46206

cve-icon Redhat

Severity :

Publid Date: 2026-05-28T00:00:00Z

Links: CVE-2026-46206 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T20:30:28Z

Weaknesses