CVE-2026-64091: batman-adv: tt: fix TOCTOU race for reported vlans
Published Jul 19, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
19 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=3.16.60<3.17
Linux Linux kernel>=4.4.217<4.5
Linux Linux kernel>=4.9.217<4.10
Linux Linux kernel>=4.14.174<4.15
Linux Linux kernel>=4.17.1<5.10.259
Linux Linux kernel>=5.11<5.15.210
Linux Linux kernel>=5.16<6.1.176
Linux Linux kernel>=6.2<6.6.143
Linux Linux kernel>=6.7<6.12.93
Linux Linux kernel>=6.13<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=4.17
Linux Linux kernel=4.17-rc7
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
debian/linux
6.1.176-16.1.187-16.12.107-16.12.111-17.2.6-17.2.8-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 6.12.111-1Fixed in 7.2.6-1Fixed in 7.2.8-1
Event History
Jul 19, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverity
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 24, 2026
Data Sourced
via Launchpad·04:09 PM
Description
Sep 29, 2026
Data Sourced
via Debian·04:13 PM
DescriptionAffected Software
Sep 30, 2026
Data Sourced
via Ubuntu·04:12 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-64091?
CVE-2026-64091 has a severity rating of critical with a CVSS score of 9.8.
2
How do I fix CVE-2026-64091?
To fix CVE-2026-64091, update your Linux kernel to the latest patched version where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2026-64091?
CVE-2026-64091 is a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability.
4
Which software is affected by CVE-2026-64091?
CVE-2026-64091 affects the Linux kernel, specifically the batman-adv networking module.
5
What are the potential impacts of CVE-2026-64091?
The potential impacts of CVE-2026-64091 include unauthorized access, data corruption, or system instability due to the TOCTOU race condition.