Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-46238— batman-adv: stop caching unowned originator pointers in BAT IV

AI Predicted 5.5 Difficulty: Moderate EPSS 0.02% · P5

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxc6c8fea29769d998d94fcec9b9f14d4b52b349d3< aafcbaf1159ea224528ca4075d0ba8c10ef374afaffected
c6c8fea29769d998d94fcec9b9f14d4b52b349d3< 6e20700f8c524ac379ba8274ff5d453023b7c006affected
c6c8fea29769d998d94fcec9b9f14d4b52b349d3< 09dc0d1a12222ffca6481916eab3cfea477b9620affected
c6c8fea29769d998d94fcec9b9f14d4b52b349d3< 67bceeb22207f1f5a402973a3a0809e5f2698f38affected
c6c8fea29769d998d94fcec9b9f14d4b52b349d3< f03e8583532941b07761c5429de7d50766fa3110affected
2.6.38affected
< 2.6.38unaffected
6.6.140≤ 6.6.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46238

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
batman-adv: stop caching unowned originator pointers in BAT IV
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointers in BAT IV BAT IV keeps the last-hop neighbor address in each neigh_node, but some paths also cache an originator pointer derived from a temporary lookup. That pointer is not owned by the neigh_node and may no longer refer to a live originator entry after purge handling runs. Stop storing the auxiliary originator pointer in the BAT IV neighbor state. When BAT IV needs the neighbor originator data, resolve it from the stored neighbor address and drop the reference again after use. [sven: avoid bonding logic for outgoing OGM]
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于BAT IV缓存未拥有的源节点指针,该指针可能在清理后失效。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux c6c8fea29769d998d94fcec9b9f14d4b52b349d3 ~ aafcbaf1159ea224528ca4075d0ba8c10ef374af -
LinuxLinux 2.6.38 -

II. Public POCs for CVE-2026-46238

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46238

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46238 (5)

Same Patch Batch · Linux · 2026-05-28 · 138 CVEs total

CVE-2026-46189RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
CVE-2026-46206batman-adv: reject new tp_meter sessions during teardown
CVE-2026-46205staging: media: atomisp: Disallow all private IOCTLs
CVE-2026-46204drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVE-2026-46203spi: cadence-quadspi: fix unclocked access on unbind
CVE-2026-46202HID: appletb-kbd: run inactivity autodim from workqueues
CVE-2026-46201drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()
CVE-2026-46200spi: mpc52xx: fix controller deregistration
CVE-2026-46199drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
CVE-2026-46198batman-adv: fix integer overflow on buff_pos
CVE-2026-46197drm/amdkfd: validate SVM ioctl nattr against buffer size
CVE-2026-46196tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-46195smb: client: validate dacloffset before building DACL pointers
CVE-2026-46193xfrm: ah: account for ESN high bits in async callbacks
CVE-2026-46194f2fs: fix node_cnt race between extent node destroy and writeback
CVE-2026-46192spi: microchip-core-qspi: don't attempt to transmit during emulated read-only dual/quad op
CVE-2026-46191fbcon: Avoid OOB font access if console rotation fails
CVE-2026-46190mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
CVE-2026-46179ASoC: SOF: Don't allow pointer operations on unconfigured streams
CVE-2026-46177ipmi: Add limits to event and receive message requests

Showing top 20 of 138 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-46238

No comments yet


Leave a comment