Impact
A logic flaw in the Linux kernel’s batman-adv module prevents the proper removal of backbone claims when a mesh interface is deleted. Because the cleanup routine is only executed when a claim hash is non‑NULL, but the hash is cleared before the routine can run, the deletion path never performs its intended work. This leads to stale state and unreleased resources guarded by the bypassed cleanup logic. The vulnerability does not provide an attack vector for code execution or privilege escalation, but it can degrade network stability and performance by allowing unremoved claims to persist.
Affected Systems
The vulnerability impacts any Linux kernel that includes the batman‑adv BLA subsystem. All kernel vendors shipping versions that have not incorporated the referenced commit series are affected. There is no specific version breakage; the fix applies to all unpatched releases with batman‑adv. The affected product is the Linux kernel, specifically the batman‑adv module used in many embedded, networking, and community distributions.
Risk and Exploitability
Risk and exploitability estimates are low. EPSS indicates less than 1% likelihood of exploitation, and the patch is not in the CISA KEV list. Successful exploitation would likely require active participation in the affected mesh network and could result in a denial‑of‑service condition rather than direct exploitation of system assets.
OpenCVE Enrichment
Debian DLA
Debian DSA