PT-2026-61407 · Linux+1 · Linux Kernel+1

CVE-2026-64090

·

Published

2026-05-12

·

Updated

2026-09-07

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the batman-adv module where the system could send empty VLAN responses when replying from the global TT state. This occurs because previous checks were only applied to local direct TT response code, potentially leading to inconsistent TT TLVLs (Type-Length-Value) and request storms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14336
CVE-2026-64090
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu