SB20260625266 - Improper resource shutdown or release in Linux kernel batman-adv
Published: June 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-52926)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in batman-adv gateway client teardown logic when tearing down and later recreating a mesh. A local user can trigger mesh teardown to cause a denial of service.
The issue leaves stale current gateway state behind across cleanup, which can break a later mesh recreation.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17e3a441111cd1a530cd6ee69a22f3161d80d810
- https://git.kernel.org/stable/c/30bda3ef4b0cac777f1a7c314cd08b8ff6437365
- https://git.kernel.org/stable/c/6de089b545db013433cf934bb4e4433dec2dd65f
- https://git.kernel.org/stable/c/9a1a8ed4facfe843bde6fdfcf7af0e9923eb2e17
- https://git.kernel.org/stable/c/a340a51ed801eab7bb454150c226323b865263cc
- https://git.kernel.org/stable/c/a3f3f1ec8aad84c5dd386c430b9c61cddd85b18f
- https://git.kernel.org/stable/c/ae7aeb0ce3c0ebbe357ed525779acac197a18086
- https://git.kernel.org/stable/c/e2ec4c712d19141ca7bf7fbbb1d842f73abaa186