Review reviewCritical

CVE-2026-64091

Linux

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct size for the VLANs is then allocated. Only then, the list of VLANs s used to fill the VLAN entries in the buffer. During this time, the meshif_vlan_list_lock is held. But the actual number of TT entries of each VLAN can still increase during this time - just not the number of VLANs in the list. But the prefilter used in the buffer size c...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct size for the VLANs is then allocated. Only then, the list of VLANs s used to fill the VLAN entries in the buffer. During this time, the meshif_vlan_list_lock is held. But the actual number of TT entries of each VLAN can still increase during this time - just not the number of VLANs in the list. But the prefilter used in the buffer size c...

Affected product and versions

Product
Linux
Affected versions
>= 16116dac23396e73c01eeee97b102e4833a4b205 < e4236bf3ec8d6bb15d0d8d825dcf9933a7d6666b, >= 16116dac23396e73c01eeee97b102e4833a4b205 < 724a8eb4155669797c96b70d70e354284ae3b5a8, >= 16116dac23396e73c01eeee97b102e4833a4b205 < 211ea59988e1cba43cb0367ad65d379b56f9c3bd, >= 16116dac23396e73c01eeee97b102e4833a4b205 < 65a1e67339aa8c95ac544b796946af388930ee23, >= 16116dac23396e73c01eeee97b102e4833a4b205 < b4d4efd4e351593c81e9293d4b4408d244fa5ee7, >= 16116dac23396e73c01eeee97b102e4833a4b205 < 4cc85aec8d3c9ab4dc716dc9f1ed36fca16b227f, >= 16116dac23396e73c01eeee97b102e4833a4b205 < 9a9c859457bc440a55773e01ff18b1bb5bab6836, >= 16116dac23396e73c01eeee97b102e4833a4b205 < 94d27005016be15ffc638b2ecbc4d58805ad7b48, >= 3134c5a32810c510f1f447c135cec346acbb71c3, >= e861e03a1b5b615ad1b57b1802b17e260eedccfe, >= 0b81edc8818903c64c4d121bc51cd5825be8cc67, >= 90ae6475b1753f0c1a4c66034b5666de3189fac8, >= 3.16.60 < 3.17, >= 4.4.217 < 4.5, >= 4.9.217 < 4.10, >= 4.14.174 < 4.15, >= 4.17
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64091 — Linux | SECUFOCUS NOW