PT-2026-94999 · Linux · Linux Kernel

CVE-2026-93203

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the batman-adv module where parallel execution of claim addition and backbone modification can lead to CRC corruption. The batadv bla add claim() function handles adding new claims or modifying existing ones for CLAIM frames. A race condition occurs when one CPU creates a claim while another CPU simultaneously processes a claim frame for the same client. This can result in the backbone gw of the claim being changed twice, causing the CRC to be incorrectly associated with the wrong backbone or missing from the correct one. Because these CRCs are not recomputed from stored claims and cannot be recovered via syncs for local backbone claims, the corruption persists.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102131
CVE-2026-93203
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel