CVE-2026-64096
Linux batman-adv kernel use-after-free allowing crash or possible kernel compromise via mesh traffic
Is CVE-2026-64096 being exploited?
Not confirmed. CVE-2026-64096 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.26% probability of exploitation in the next 30 days.
How severe is CVE-2026-64096?
CVE-2026-64096 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64096?
Yes. A fix has been recorded for CVE-2026-64096. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64096 affect?
CVE-2026-64096 affects Linux kernel (batman-adv module), Routers/embedded devices using batman-adv, Mesh network nodes. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64096?
Install kernel update with batman-adv fix or disable batman-adv until patched
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote mesh node can trigger kernel use-after-free leading to crash/DoS and potential kernel RCE or privilege escalation.
Patch when possible
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < ff3a4487ead475e27b43280b8ee3d8464fe280e1
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < 78a63fb2f7d5630d1c1f2859a20d4e4226863b41
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < ced48f55bac73f0822eae90509e51b42b4f646c8
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < 70bcb678561f0fb58f33270fc73f12f3be72b878
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < aef897c9d2dd0d9339167fb82b62beff68d076cb
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < 8a3707653ab658e082ccd992e92594e01b09a3fc
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < edfb1e094104a50f931553dc82ac59246569fd32
- affected>= ab49886e3da73b6b35ece21006e191910427bb30 and < 20c2d6a20ca936f5aaa6dd40f73f262ac45c87cc
- affected3.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.