CVE-2026-93204
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: atomically update mac addresses When a MAC address is updated in batadv_dat_entry_add(), it is done using a simple copy function. A parallel reader might only see parts of this update. In worst case, the reader is transporting the half updated MAC address over the network or is creating an ARP response using it - poisoning the ARP cache. atomic64_t can be used to store the 48 bit of a mac address. A reader will then either see the old mac address or the new one - never a mixture of both.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/159360a0de831845c4500b4f8638decdcd624040
- https://git.kernel.org/stable/c/1674855a5b6eacfe35f4db3095d7055c25467274
- https://git.kernel.org/stable/c/259db2c04586d40b82c5c3002b1e28b0698a0bb7
- https://git.kernel.org/stable/c/66238e2a74eca5dabf85b0cd2c3c944e474dc2fd
- https://git.kernel.org/stable/c/a5e4d6cb4f6848b8906c1c493f99a8ccc0638515
- https://git.kernel.org/stable/c/e6de568d3eda3e3c01c868fabd7a9535d5ee4a73
- https://git.kernel.org/stable/c/f68038c77a2f38c09c7e2e4f7fa1f4e246fdf2c9
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.