CVE-2026-64089
Linux kernel batman-adv sign-extension bug may leak uninitialized kernel memory
Is CVE-2026-64089 being exploited?
Not confirmed. CVE-2026-64089 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.55% probability of exploitation in the next 30 days.
How severe is CVE-2026-64089?
CVE-2026-64089 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64089?
Yes. A fix has been recorded for CVE-2026-64089. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64089 affect?
CVE-2026-64089 affects Linux kernel (batman-adv module), Devices running batman-adv mesh networking. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64089?
Apply vendor/kernel update that includes the batman-adv fix immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Uninitialized kernel memory can be leaked via batman-adv TT responses, enabling information disclosure and aiding privilege escalation or remote attacks.
Patch when possible
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < 6314089acf0ddf64376fdc0b1420695504c73f52
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < 55dc41fe8821e9a849e147255ad572bc933a9d15
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < c424e8519ac78eac5d9f4eecf06208a0d619ec14
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < 22d59c72f4a47ffec121d0610f70d0d70c3c11c8
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < eb235472b52ef36981c5aad330485eaf2382c53b
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < 179eb62506a02d00370bd6478898cb632e10986c
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < d29abf70c665730e249d2ec8e1402095ae26bcee
- affected>= a73105b8d4c765d9ebfb664d0a66802127d8e4c7 and < fc92cdfcb295cefa4344d71a527d61b638b7bfc4
- affected3.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.