Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52919— batman-adv: fix tp_meter counter underflow during shutdown

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 4.8版本存在安全漏洞,该漏洞源于batman-adv中tp_meter计数器在关闭过程中存在下溢,可能导致sender kthread无限循环,进而在接口移除时导致释放后重用。以下版本受到影响:4.8版本。

CVSS 7.8 · High EPSS 0.12% · P2

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e< e75e2ab463b5b34df6b98f94d740aff327ce9f6b affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< abae88fa254f2981d39ac003a7b302528a22af64 affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< c66d20a3ff095e3f000551d208ec2606616db15c affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< c1bac194733aabd731aafa6a01350c229e187dba affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< 01cefc5923889e29dbb5f281c3d457714ceb9c00 affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< 90ae3eae06b7b8ab9f6250b9497c860915b4c17b affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< aeae11c5dad9cd0d50723890bdd866f8e6db2e7d affected
33a3bb4a3345bb511f9c69c913da95d4693e2a4e< 94f3b133168d1c49895e7cc6afbcf1cc0b354602 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52919

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
batman-adv: fix tp_meter counter underflow during shutdown
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during shutdown batadv_tp_sender_shutdown() unconditionally decrements the "sending" atomic counter. If multiple paths (e.g. timeout, user cancel, and normal finish) call this function, the counter can underflow to -1. Since the sender logic treats any non-zero value as "still sending", a negative value causes the sender kthread to loop indefinitely. This leads to a use-after-free when the interface is removed while the zombie thread is still active. Fix this by using atomic_xchg() to ensure the counter only transitions from 1 to 0 once. [sven: added missing change in batadv_tp_send]
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 4.8版本存在安全漏洞,该漏洞源于batman-adv中tp_meter计数器在关闭过程中存在下溢,可能导致sender kthread无限循环,进而在接口移除时导致释放后重用。以下版本受到影响:4.8版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e ~ e75e2ab463b5b34df6b98f94d740aff327ce9f6b -
Linux Linux 4.8 -

II. Public POCs for CVE-2026-52919

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52919

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52919 (8)

Same Patch Batch · Linux · 2026-06-24 · 219 CVEs total

CVE-2026-53088 9.8 CRITICAL net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-53046 9.8 CRITICAL ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
CVE-2026-53049 9.8 CRITICAL gfs2: add some missing log locking
CVE-2026-52955 9.8 CRITICAL libceph: Fix potential out-of-bounds access in crush_decode()
CVE-2026-53045 9.8 CRITICAL memory: tegra124-emc: Fix dll_change check
CVE-2026-52982 9.8 CRITICAL net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
CVE-2026-52986 9.8 CRITICAL netfilter: nf_conntrack_sip: don't use simple_strtoul
CVE-2026-52989 9.8 CRITICAL nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
CVE-2026-52993 9.8 CRITICAL tipc: fix double-free in tipc_buf_append()
CVE-2026-53002 9.8 CRITICAL netfilter: conntrack: remove sprintf usage
CVE-2026-52931 9.8 CRITICAL batman-adv: tp_meter: avoid use of uninit sender vars
CVE-2026-53055 9.8 CRITICAL crypto: hisilicon/sec2 - prevent req used-after-free for sec
CVE-2026-52924 9.8 CRITICAL sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-53006 9.8 CRITICAL ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-52914 9.8 CRITICAL batman-adv: fix fragment reassembly length accounting
CVE-2026-53086 9.8 CRITICAL net: bcmgenet: fix racing timeout handler
CVE-2026-53010 9.8 CRITICAL ksmbd: fix use-after-free in smb2_open during durable reconnect
CVE-2026-52999 9.1 CRITICAL netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVE-2026-52958 9.1 CRITICAL libceph: Fix potential out-of-bounds access in osdmap_decode()
CVE-2026-53043 9.1 CRITICAL ocfs2/dlm: validate qr_numregions in dlm_match_regions()

Showing top 20 of 219 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-52919

No comments yet


Leave a comment