CVE-2026-64218 is a vulnerability in Linux Kernel
Published on July 24, 2026
batman-adv: bla: fix report_work leak on backbone_gw purge
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: bla: fix report_work leak on backbone_gw purge
batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
but fails to properly handle their associated report_work:
- If report_work is running, the purge must wait for it to finish before
freeing the backbone_gw, otherwise the worker may access freed memory
(e.g. bat_priv).
- If report_work is pending, the purge must cancel it and release the
reference held for that pending work item.
The previous implementation called hlist_for_each_entry_safe() inside a
spin_lock_bh() section, but cancel_work_sync() may sleep and therefore
cannot be called from within a spinlock-protected region.
Restructure the loop to handle one entry per spinlock critical section:
acquire the lock, find the next entry to purge, remove it from the hash
list, then release the lock before calling cancel_work_sync() and
dropping the hash_entry reference. Repeat until no more entries require
purging.
Products Associated with CVE-2026-64218
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below ce2c0ee4d76d5ee4b391fe0e31334361e25030ec is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below 3423a45e5c3d3c5129f88143a9a969787d7d5a0a is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below f1303adb1e59582f76c22798a2e2e150e054a9e7 is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below 48663158222b3b7f6ee6791a67d512ede7fc94bb is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below eeddd7bab3d59c1e98642a204141f8c5d6194707 is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below c6de1a5a9c406e30b91f1515a6ce05cc84023baa is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below 95a7034661274cf5985708bd2f6d86ee46f88fa9 is affected.
- Version 23721387c409087fd3b97e274f34d3ddc0970b74 and below 0459430add32ea41f3e2ef9351610e6d33627a6b is affected.
- Version 3.5 is affected.
- Before 3.5 is unaffected.
- Version 5.10.258, <= 5.10.* is unaffected.
- Version 5.15.209, <= 5.15.* is unaffected.
- Version 6.1.175, <= 6.1.* is unaffected.
- Version 6.6.142, <= 6.6.* is unaffected.
- Version 6.12.92, <= 6.12.* is unaffected.
- Version 6.18.34, <= 6.18.* is unaffected.
- Version 7.0.11, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.