Use-after-free in Linux kernel - CVE-2026-64218
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in batadv_bla_purge_backbone_gw() in the bridge loop avoidance component when purging stale backbone gateway entries. A local user can trigger report_work to access freed memory to cause a denial of service.
The issue occurs when associated report_work is still running or pending during backbone gateway cleanup.
How to mitigate CVE-2026-64218
Sources
- https://git.kernel.org/stable/c/0459430add32ea41f3e2ef9351610e6d33627a6b
- https://git.kernel.org/stable/c/3423a45e5c3d3c5129f88143a9a969787d7d5a0a
- https://git.kernel.org/stable/c/48663158222b3b7f6ee6791a67d512ede7fc94bb
- https://git.kernel.org/stable/c/95a7034661274cf5985708bd2f6d86ee46f88fa9
- https://git.kernel.org/stable/c/c6de1a5a9c406e30b91f1515a6ce05cc84023baa
- https://git.kernel.org/stable/c/ce2c0ee4d76d5ee4b391fe0e31334361e25030ec
- https://git.kernel.org/stable/c/eeddd7bab3d59c1e98642a204141f8c5d6194707
- https://git.kernel.org/stable/c/f1303adb1e59582f76c22798a2e2e150e054a9e7