Impact
This vulnerability is a race condition in the Linux kernel’s batman-adv module that can corrupt the CRC16 checksums used to verify network claim entries. When two CPUs concurrently process claim frames, a claim’s CRC can be mistakenly removed from one backbone and added to another, resulting in incorrect checksum totals for both backbones. The bug does not recompute the CRC from stored claims, and therefore the corrupted value can persist until synced. The consequence is a failure to correctly validate the integrity of claim tables, which may lead to misrouting, network instability, or denial of service in the mesh network that relies on batman-adv. The weakness is identified as a concurrency issue (CWE-362).
Affected Systems
The affected product is the Linux kernel (any distribution) when the kernel includes the batman-adv implementation in the mainline kernel. Specific kernel releases are not listed, so any build that incorporates the current batman-adv code before the fix is potentially vulnerable. The vulnerability applies to all nodes that rely on batman-adv for mesh networking.
Risk and Exploitability
The CVSS score of 7.1 categorises the issue as high severity, but its EPSS probability of less than 1% indicates a low likelihood of exploitation at present. The problem is not currently listed in CISA’s KEV catalogue, so no widespread known exploits have been reported. Based on the description, it is inferred that an attacker could trigger the corruption by injecting crafted claim frames or by performing rapid claim updates at a node with a vulnerable kernel. Such activity would likely require local privilege or at least network access to the mesh, and may only affect nodes running batman-adv. The attack vector is inferred, as the CVE data does not disclose the exact method of triggering the race condition.
OpenCVE Enrichment
Debian DLA
Debian DSA