PT-2026-94999 · Linux · Linux Kernel
CVE-2026-93203
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
batman-adv module where parallel execution of claim addition and backbone modification can lead to CRC corruption. The batadv bla add claim() function handles adding new claims or modifying existing ones for CLAIM frames. A race condition occurs when one CPU creates a claim while another CPU simultaneously processes a claim frame for the same client. This can result in the backbone gw of the claim being changed twice, causing the CRC to be incorrectly associated with the wrong backbone or missing from the correct one. Because these CRCs are not recomputed from stored claims and cannot be recovered via syncs for local backbone claims, the corruption persists.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel