Linux aws: In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node RCU release… (CVE-2026-64096)
In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node RCU release batadv_mcast_purge_orig() removes entries from RCU-protected hlists but does not wait for an RCU grace period before returning. Concurrent RCU readers may still accesses references to those entries at the point of removal. RCU-protected readers trying to operate on entries like orig->mcast_want_all_ipv6_node will then access already freed memory. Fix this by moving batadv_mcast_purge_orig() to batadv_orig_node_release(), just before the call_rcu() invocation. This ensures RCU readers that were active at purge time have drained before the orig_node memory is reclaimed.
AI Analysis
Technical Summary
The Linux kernel's batman-adv multicast subsystem contained a use-after-free vulnerability in the orig_node RCU release mechanism. Specifically, batadv_mcast_purge_orig() removed entries from RCU-protected hash lists but did not wait for an RCU grace period before returning, allowing concurrent RCU readers to access freed memory such as orig->mcast_want_all_ipv6_node. The fix moves batadv_mcast_purge_orig() to batadv_orig_node_release(), just before the call_rcu() invocation, ensuring that RCU readers active during purge have drained before memory reclamation. This vulnerability was assigned CVE-2026-64096 with a CVSS 3.1 score of 8.8 (high impact). Multiple linux-aws kernel versions prior to 5.15.0-1112.119~20.04.1 and others are affected. The vendor advisory from Ubuntu confirms the availability of patches and recommends updating and rebooting to apply fixes.
Potential Impact
Exploitation of this use-after-free vulnerability could allow attackers to cause memory corruption in the kernel, potentially leading to system crashes or privilege escalation. The CVSS score of 8.8 indicates high impact on confidentiality, integrity, and availability. However, no known exploits in the wild have been reported. The vulnerability affects the stability and security of systems running affected linux-aws kernel versions.
Mitigation Recommendations
A patch is available from the vendor. Users should update their linux-aws kernel packages to versions at or above 5.15.0-1112.119~20.04.1 (and other specified fixed versions) and reboot the system to apply the fix. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required. Follow the vendor's update instructions carefully to ensure complete remediation.
Linux aws: In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node RCU release… (CVE-2026-64096)
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node RCU release batadv_mcast_purge_orig() removes entries from RCU-protected hlists but does not wait for an RCU grace period before returning. Concurrent RCU readers may still accesses references to those entries at the point of removal. RCU-protected readers trying to operate on entries like orig->mcast_want_all_ipv6_node will then access already freed memory. Fix this by moving batadv_mcast_purge_orig() to batadv_orig_node_release(), just before the call_rcu() invocation. This ensures RCU readers that were active at purge time have drained before the orig_node memory is reclaimed.
CVSS v3.1
Score 8.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's batman-adv multicast subsystem contained a use-after-free vulnerability in the orig_node RCU release mechanism. Specifically, batadv_mcast_purge_orig() removed entries from RCU-protected hash lists but did not wait for an RCU grace period before returning, allowing concurrent RCU readers to access freed memory such as orig->mcast_want_all_ipv6_node. The fix moves batadv_mcast_purge_orig() to batadv_orig_node_release(), just before the call_rcu() invocation, ensuring that RCU readers active during purge have drained before memory reclamation. This vulnerability was assigned CVE-2026-64096 with a CVSS 3.1 score of 8.8 (high impact). Multiple linux-aws kernel versions prior to 5.15.0-1112.119~20.04.1 and others are affected. The vendor advisory from Ubuntu confirms the availability of patches and recommends updating and rebooting to apply fixes.
Potential Impact
Exploitation of this use-after-free vulnerability could allow attackers to cause memory corruption in the kernel, potentially leading to system crashes or privilege escalation. The CVSS score of 8.8 indicates high impact on confidentiality, integrity, and availability. However, no known exploits in the wild have been reported. The vulnerability affects the stability and security of systems running affected linux-aws kernel versions.
Mitigation Recommendations
A patch is available from the vendor. Users should update their linux-aws kernel packages to versions at or above 5.15.0-1112.119~20.04.1 (and other specified fixed versions) and reboot the system to apply the fix. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required. Follow the vendor's update instructions carefully to ensure complete remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jhvq-hvr2-2mgr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64096"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27a82a4a8d598912b566
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 08/22/2026, 14:29:48 UTC
Last updated: 08/31/2026, 22:52:13 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.