Linux Kernel batman-adv tp_meter Session Management Vulnerability

Vulnerability

A vulnerability in the Linux kernel's batman-adv module has been addressed. This issue prevented the throughput meter (tp_meter) from initiating new sender or receiver sessions after the mesh state had transitioned away from active. The vulnerability was introduced in the tp_meter implementation and could lead to improper session management during critical network operations.

Impact

The vulnerability could cause disruptions in network performance by allowing tp_meter sessions to be improperly managed, potentially leading to uncoordinated data transmission or reception.

Reproduction

The vulnerability can be reproduced by allowing the mesh state to transition out of BATADV_MESH_ACTIVE, and then attempting to start new tp_meter sessions. The sessions should not be initiated, indicating that the vulnerability is present.

Remediation

Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the Linux Kernel Archives.

Added: May 28, 2026, 11:26 AM
Updated: May 28, 2026, 11:26 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
9.6
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.