Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: bla: fix freeing of claims on meshif deletion

When the mesh interface is getting deleted, then
batadv_bla_del_backbone_claims() (via batadv_bla_purge_backbone_gw()) could
make sure that all claims gets removed. But this function is only executed
when bat_priv->bla.claim_hash is not NULL. And since batadv_bla_free() is
always setting it to NULL before it is (indirectly) called, it was never
actually executed.

But the batadv_bla_purge_claims() -> batadv_handle_unclaim() is at the
moment too fragile because the BLA code is not handling the rehashing in
batadv_bla_update_orig_address(). The stored backbone address doesn't have
to be the one actually used for the hash bucket selection during the
initial adding of the backbone. The batadv_handle_unclaim() can therefore
fail to find the respective backbone for the unclaim and then stop the
deletion.

But the actual backbone_gw object is not needed for the unclaim because all
relevant information is always provided by the caller. And the check for
the existence of the backbone_gw doesn't provide any additional security
check for the deletion of a claim.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion / Denial of Service
Action: Apply Patch
AI Analysis

Impact

A logic flaw in the Linux kernel’s batman-adv module prevents the proper removal of backbone claims when a mesh interface is deleted. Because the cleanup routine is only executed when a claim hash is non‑NULL, but the hash is cleared before the routine can run, the deletion path never performs its intended work. This leads to stale state and unreleased resources guarded by the bypassed cleanup logic. The vulnerability does not provide an attack vector for code execution or privilege escalation, but it can degrade network stability and performance by allowing unremoved claims to persist.

Affected Systems

The vulnerability impacts any Linux kernel that includes the batman‑adv BLA subsystem. All kernel vendors shipping versions that have not incorporated the referenced commit series are affected. There is no specific version breakage; the fix applies to all unpatched releases with batman‑adv. The affected product is the Linux kernel, specifically the batman‑adv module used in many embedded, networking, and community distributions.

Risk and Exploitability

Risk and exploitability estimates are low. EPSS indicates less than 1% likelihood of exploitation, and the patch is not in the CISA KEV list. Successful exploitation would likely require active participation in the affected mesh network and could result in a denial‑of‑service condition rather than direct exploitation of system assets.

Generated by OpenCVE AI on September 18, 2026 at 07:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a kernel version that includes the batman-adv claim‑cleanup fix from the referenced commit series
  • Recompile the kernel with the latest batman‑adv patches if the distribution does not provide a patched binary
  • Monitor the stability of mesh networks for abnormal claim persistence after updates

Generated by OpenCVE AI on September 18, 2026 at 07:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-773

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix freeing of claims on meshif deletion When the mesh interface is getting deleted, then batadv_bla_del_backbone_claims() (via batadv_bla_purge_backbone_gw()) could make sure that all claims gets removed. But this function is only executed when bat_priv->bla.claim_hash is not NULL. And since batadv_bla_free() is always setting it to NULL before it is (indirectly) called, it was never actually executed. But the batadv_bla_purge_claims() -> batadv_handle_unclaim() is at the moment too fragile because the BLA code is not handling the rehashing in batadv_bla_update_orig_address(). The stored backbone address doesn't have to be the one actually used for the hash bucket selection during the initial adding of the backbone. The batadv_handle_unclaim() can therefore fail to find the respective backbone for the unclaim and then stop the deletion. But the actual backbone_gw object is not needed for the unclaim because all relevant information is always provided by the caller. And the check for the existence of the backbone_gw doesn't provide any additional security check for the deletion of a claim.
Title batman-adv: bla: fix freeing of claims on meshif deletion
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:34.089Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:04.890

Modified: 2026-09-16T11:17:04.890

Link: CVE-2026-89948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-773

    Missing Reference to Active File Descriptor or Handle