batman-adv tt_buff_len sign extension vulnerability
CVE-2026-64088 Published on July 19, 2026
batman-adv: tt: fix negative tt_buff_len
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: fix negative tt_buff_len
batadv_orig_node::tt_buff_len was declared as s16, but the field is never
intended to hold a negative value. When a value greater than 32767 is
assigned, it wraps to a negative signed integer.
In batadv_send_other_tt_response(), tt_buff_len is temporarily widened to
s32. The incorrectly negative s16 value propagates into the s32, causing
batadv_tt_prepare_tvlv_global_data() to allocate a full sized buffer but
populates only a small portion of it with the collected changeset. All
remaining bits are kept uninitialized.
Using an u16 avoids this type confusion and ensures that no (negative) sign
extension is performed in batadv_send_other_tt_response().
Products Associated with CVE-2026-64088
stack.watch emails you whenever new vulnerabilities are published in Linux Kernel or Canonical Ubuntu Linux. Just hit a watch button to start following.
Affected Versions
Linux:- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below 4c4c2f340f4c27373bfcac8dc5032ce7bb474e47 is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below 33e5ede7ce6d92e531920d4bbd6d3e18ef1c6430 is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below 3c96dff00998314983b68a3e7caac07a66ebe496 is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below 32edd2a28e112064020a2f319a8cb8a9e5a09767 is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below 4dab98961426d0cf6a1599cda6950b7596ca2fcd is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below 730de8733dd90f70d7580a9b329b971f8e1474a2 is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below ed28ead3420c373a7928622f114bc6168075d1e1 is affected.
- Version a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and below b64963a2ceeb7529310b6cf253a1e540784422f4 is affected.
- Version 3.1 is affected.
- Before 3.1 is unaffected.
- Version 5.10.258, <= 5.10.* is unaffected.
- Version 5.15.209, <= 5.15.* is unaffected.
- Version 6.1.175, <= 6.1.* is unaffected.
- Version 6.6.142, <= 6.6.* is unaffected.
- Version 6.12.92, <= 6.12.* is unaffected.
- Version 6.18.34, <= 6.18.* is unaffected.
- Version 7.0.11, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.