Review reviewHigh

CVE-2026-64093

Linux

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming itself between the two calls. This double-deletion hack relied on the sending status being set to 0 to suppress re-arming. Replace both calls with a single timer_shutdown_sync(). This function both waits for any running timer callback to complete (like timer_delete_sync()) and permanently disarms the timer so it cannot be re-armed afterwa...

CVSS
8.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming itself between the two calls. This double-deletion hack relied on the sending status being set to 0 to suppress re-arming. Replace both calls with a single timer_shutdown_sync(). This function both waits for any running timer callback to complete (like timer_delete_sync()) and permanently disarms the timer so it cannot be re-armed afterwa...

Affected product and versions

Product
Linux
Affected versions
>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 00bf4bb9947b1190a8be8d9b6a1bcbfa3707785c, >= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 74a76634055462833446684fd526d73c290ea43a, >= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 5bc2d50fb66b46f86543d5153a188eb1486d0b6e, >= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < f86b20ec8d17d77bddc02c5c86cfa2389d84ecff, >= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 770bf0a35f0620b526fd4193889d1e77084e4c43, >= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 933880a8bc9b4042223a79255c0b1021cdc36991, >= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < d5487249a81ea658717614009c8f46acc5b7101a, >= 4.8
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available