IT

Tracker / CVE-2026-46233

CVE-2026-46233

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims When batadv_bla_purge_claims() goes through the list of claims, it is only traversing the hash list with an rcu_read_lock(). Due to a potential parallel batadv_claim_put(), it can happen that it encounters a claim which was actually in the process of being released+freed by batadv_claim_release(). In this case, backbone_gw is set to NULL before the delayed RCU kfree is started. Calling batadv_bla_claim_get_backbone_gw() is then no longer allowed because it would cause a NULL-ptr derefence. To avoid this, only claims with a valid reference counter must be purged. All others are already taken care of.

Affected products and versions

linux linux_kernel
linux linux_kernel · 3.5 → 5.10.258
linux linux_kernel · 5.11 → 5.15.209
linux linux_kernel · 5.16 → 6.1.175
linux linux_kernel · 6.13 → 6.18.32
linux linux_kernel · 6.19 → 7.0.9
linux linux_kernel · 6.2 → 6.6.140
linux linux_kernel · 6.7 → 6.12.90

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References