Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: atomically update mac addresses

When a MAC address is updated in batadv_dat_entry_add(), it is done using a
simple copy function. A parallel reader might only see parts of this
update. In worst case, the reader is transporting the half updated MAC
address over the network or is creating an ARP response using it -
poisoning the ARP cache.

atomic64_t can be used to store the 48 bit of a mac address. A reader will
then either see the old mac address or the new one - never a mixture of
both.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote ARP Cache Poisoning
Action: Immediate Patch
AI Analysis

Impact

A race condition in the batman-adv module can cause a MAC address to be partially updated while another process reads it. The reader may see an incomplete MAC address and transmit it over the network or include it in an ARP response, which enables an attacker to poison the ARP cache of neighboring devices. This flaw can lead to Man‑in‑the‑Middle attacks, packet loss, or denial of service. The weakness is a classic race condition that allows inconsistent state usage.

Affected Systems

The vulnerability affects Linux kernels that include the batman-adv networking stack. It is present in versions that have not yet applied the patch that atomically updates MAC addresses using atomic64_t. The exact kernel releases are those prior to the commit referenced in the source list.

Risk and Exploitability

The EPSS score is reported as <1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack does not require special privileges and could be triggered by a local or remote user on the same bridged network segment. The CVSS score is not provided, but based on the potential impact, the severity can be considered high. Exploitability would involve an attacker controlling network traffic to the vulnerable node, possibly in a multi‑tenant or shared‑snetwork environment. The attack vector is inferred from the race condition during MAC address updates.

Generated by OpenCVE AI on September 19, 2026 at 08:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the batadv_dat_entry_add() patch or the specific commit that adds atomic64_t handling.
  • If an upgrade cannot be performed immediately, unload or disable the batmand-adv module until the patch is applied.
  • Configure network monitoring or ARP spoofing detection tools to alert administrators to unexpected ARP traffic until the fix is in place.

Generated by OpenCVE AI on September 19, 2026 at 08:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 03 Oct 2026 11:15:00 +0000


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: atomically update mac addresses When a MAC address is updated in batadv_dat_entry_add(), it is done using a simple copy function. A parallel reader might only see parts of this update. In worst case, the reader is transporting the half updated MAC address over the network or is creating an ARP response using it - poisoning the ARP cache. atomic64_t can be used to store the 48 bit of a mac address. A reader will then either see the old mac address or the new one - never a mixture of both.
Title batman-adv: dat: atomically update mac addresses
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:57:06.832Z

Reserved: 2026-09-17T16:02:15.093Z

Link: CVE-2026-93204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:16.773

Modified: 2026-10-03T11:17:46.550

Link: CVE-2026-93204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:45:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')