CVE-2026-64096: Linux Kernel
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node RCU release batadv_mcast_purge_orig() removes entries from RCU-protected hlists but does not wait for an RCU grace period before returning. Concurrent RCU readers may still accesses references to those entries at the point of removal. RCU-protected readers trying to operate on entries like orig->mcast_want_all_ipv6_node will then access already freed memory. Fix this by moving batadv_mcast_purge_orig() to batadv_orig_node_release(), just before the call_rcu() invocation. This ensures RCU readers that were active at purge time have drained before the orig_node memory is reclaimed.
Affected products
- Linux Linux Kernel: from 3.15, before 5.10.258 (fixed in 5.10.258); from 5.11, before 5.15.209 (fixed in 5.15.209); from 5.16, before 6.1.175 (fixed in 6.1.175); from 6.2, before 6.6.142 (fixed in 6.6.142); from 6.7, before 6.12.92 (fixed in 6.12.92); from 6.13, before 6.18.34 (fixed in 6.18.34); …
Published 2026-07-19. Last modified 2026-08-11.