Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: bla: avoid CRC corruption due to parallel claim add

batadv_bla_add_claim() is used to add claims and modify the backbone of
claims for CLAIM frames from remote backbones and local packets. When it
handles a claim, it needs to either

* add the new claim's CRC to the backbone CRC
* remove the already existing claim's CRC from the old backbone and add it
to the new backbone

But when the "new" claim code was running in parallel to the "change
backbone" code, it can happen that the CRC was invalid because the
backbone_gw of the claim was changed twice in the "new" claim code path:

* CPU0 creates the claim for gateway A and publishes it in the claim
hash. The crc16 of the address has not yet been added to A's crc at
this point.

* CPU1 processes a claim frame of gateway B for the same client, finds
the just published claim, and performs the ownership change: it
switches the pointer to B, removes the crc16 from A's crc - which
never contained it - and adds it to B's crc.

* CPU0 continues behind the creation branch, unconditionally switches
the pointer back to A without compensating B's crc (its remove_crc
is false for the creation path), and finally adds the crc16 to A's
crc

The CRC is then wrong for both:

* claim belongs to A: but CRC is not part of backbone A's CRC
* claim doesn't belong to B: CRC is still part of backbone B's CRC

This wrong CRC is never recomputated from the stored claims. For local
backbone claims, this can also not recovered using syncs.

To avoid this, split the functionality in clear separate parts:

* new claim which always adds claim CRC to the backbone CRC (but never
changes the already set backbone_gw of the claim back)

* update of existing claim which automatically changes the backbone_gw
entry and only updates both backbone CRCs when there was an actual change
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data integrity and availability due to corrupted checksum values
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a race condition in the Linux kernel’s batman-adv module that can corrupt the CRC16 checksums used to verify network claim entries. When two CPUs concurrently process claim frames, a claim’s CRC can be mistakenly removed from one backbone and added to another, resulting in incorrect checksum totals for both backbones. The bug does not recompute the CRC from stored claims, and therefore the corrupted value can persist until synced. The consequence is a failure to correctly validate the integrity of claim tables, which may lead to misrouting, network instability, or denial of service in the mesh network that relies on batman-adv. The weakness is identified as a concurrency issue (CWE-362).

Affected Systems

The affected product is the Linux kernel (any distribution) when the kernel includes the batman-adv implementation in the mainline kernel. Specific kernel releases are not listed, so any build that incorporates the current batman-adv code before the fix is potentially vulnerable. The vulnerability applies to all nodes that rely on batman-adv for mesh networking.

Risk and Exploitability

The CVSS score of 7.1 categorises the issue as high severity, but its EPSS probability of less than 1% indicates a low likelihood of exploitation at present. The problem is not currently listed in CISA’s KEV catalogue, so no widespread known exploits have been reported. Based on the description, it is inferred that an attacker could trigger the corruption by injecting crafted claim frames or by performing rapid claim updates at a node with a vulnerable kernel. Such activity would likely require local privilege or at least network access to the mesh, and may only affect nodes running batman-adv. The attack vector is inferred, as the CVE data does not disclose the exact method of triggering the race condition.

Generated by OpenCVE AI on September 19, 2026 at 22:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the batman-adv CRC race-condition fix.
  • If a patch is not yet available, disable batman-adv on vulnerable nodes to prevent checksum corruption.
  • Monitor mesh network performance for abnormal claim or routing behavior and isolate any node exhibiting repeated checksum inconsistencies.

Generated by OpenCVE AI on September 19, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 19 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid CRC corruption due to parallel claim add batadv_bla_add_claim() is used to add claims and modify the backbone of claims for CLAIM frames from remote backbones and local packets. When it handles a claim, it needs to either * add the new claim's CRC to the backbone CRC * remove the already existing claim's CRC from the old backbone and add it to the new backbone But when the "new" claim code was running in parallel to the "change backbone" code, it can happen that the CRC was invalid because the backbone_gw of the claim was changed twice in the "new" claim code path: * CPU0 creates the claim for gateway A and publishes it in the claim hash. The crc16 of the address has not yet been added to A's crc at this point. * CPU1 processes a claim frame of gateway B for the same client, finds the just published claim, and performs the ownership change: it switches the pointer to B, removes the crc16 from A's crc - which never contained it - and adds it to B's crc. * CPU0 continues behind the creation branch, unconditionally switches the pointer back to A without compensating B's crc (its remove_crc is false for the creation path), and finally adds the crc16 to A's crc The CRC is then wrong for both: * claim belongs to A: but CRC is not part of backbone A's CRC * claim doesn't belong to B: CRC is still part of backbone B's CRC This wrong CRC is never recomputated from the stored claims. For local backbone claims, this can also not recovered using syncs. To avoid this, split the functionality in clear separate parts: * new claim which always adds claim CRC to the backbone CRC (but never changes the already set backbone_gw of the claim back) * update of existing claim which automatically changes the backbone_gw entry and only updates both backbone CRCs when there was an actual change
Title batman-adv: bla: avoid CRC corruption due to parallel claim add
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:32.968Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93203

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:16.627

Modified: 2026-09-18T18:18:25.057

Link: CVE-2026-93203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:00:10Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')