PT-2026-61411 · Linux+1 · Linux Kernel+1

CVE-2026-64094

·

Published

2026-05-19

·

Updated

2026-09-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL-pointer dereference occurs in the batman-adv module when a hard interface is retrieved as the primary interface of a mesh interface but becomes decoupled from it before the rtnl lock is held. This results in the pointer from the primary hard interface to the mesh interface being set to NULL. The issue manifests when the system attempts to send an ARP request using the mesh interface without first verifying that the mesh iface is non-NULL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14417
CVE-2026-64094
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu