SB20260720143 - Use of Uninitialized Variable in Linux kernel batman-adv
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Uninitialized Variable (CVE-ID: CVE-2026-64088)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to uninitialized memory exposure in batadv_send_other_tt_response() and batadv_tt_prepare_tvlv_global_data() when handling tt changeset response data. A remote attacker can trigger processing of an oversized tt_buff_len value to disclose sensitive information.
The issue is caused by a signed integer field wrapping to a negative value and then being widened with sign extension, resulting in a fully allocated buffer that is only partially initialized.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/32edd2a28e112064020a2f319a8cb8a9e5a09767
- https://git.kernel.org/stable/c/33e5ede7ce6d92e531920d4bbd6d3e18ef1c6430
- https://git.kernel.org/stable/c/3c96dff00998314983b68a3e7caac07a66ebe496
- https://git.kernel.org/stable/c/4c4c2f340f4c27373bfcac8dc5032ce7bb474e47
- https://git.kernel.org/stable/c/4dab98961426d0cf6a1599cda6950b7596ca2fcd
- https://git.kernel.org/stable/c/730de8733dd90f70d7580a9b329b971f8e1474a2
- https://git.kernel.org/stable/c/b64963a2ceeb7529310b6cf253a1e540784422f4
- https://git.kernel.org/stable/c/ed28ead3420c373a7928622f114bc6168075d1e1