CVE-2026-93204
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: atomically update mac addresses
When a MAC address is updated in batadv_dat_entry_add(), it is done using a simple copy function. A parallel reader might only see parts of this update. In worst case, the reader is transporting the half updated MAC address over the network or is creating an ARP response using it - poisoning the ARP cache.
atomic64_t can be used to store the 48 bit of a mac address. A reader will then either see the old mac address or the new one - never a mixture of both.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/159360a0de831845c4500b4f8638decdcd624040
- https://git.kernel.org/stable/c/1674855a5b6eacfe35f4db3095d7055c25467274
- https://git.kernel.org/stable/c/181012b3d29c51197c235ee5871fc7512c736855
- https://git.kernel.org/stable/c/259db2c04586d40b82c5c3002b1e28b0698a0bb7
- https://git.kernel.org/stable/c/66238e2a74eca5dabf85b0cd2c3c944e474dc2fd
- https://git.kernel.org/stable/c/a5e4d6cb4f6848b8906c1c493f99a8ccc0638515
- https://git.kernel.org/stable/c/e6de568d3eda3e3c01c868fabd7a9535d5ee4a73
- https://git.kernel.org/stable/c/f68038c77a2f38c09c7e2e4f7fa1f4e246fdf2c9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93204",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "181012b3d29c51197c235ee5871fc7512c736855",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "159360a0de831845c4500b4f8638decdcd624040",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "259db2c04586d40b82c5c3002b1e28b0698a0bb7",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "1674855a5b6eacfe35f4db3095d7055c25467274",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "66238e2a74eca5dabf85b0cd2c3c944e474dc2fd",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "a5e4d6cb4f6848b8906c1c493f99a8ccc0638515",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "f68038c77a2f38c09c7e2e4f7fa1f4e246fdf2c9",
"versionType": "git"
},
{
"status": "affected",
"version": "2f1dfbe185075a50dc8f0490a136377af53a1c62",
"lessThan": "e6de568d3eda3e3c01c868fabd7a9535d5ee4a73",
"versionType": "git"
}
],
"programFiles": [
"net/batman-adv/distributed-arp-table.c",
"net/batman-adv/types.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/batman-adv/distributed-arp-table.c",
"net/batman-adv/types.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:16.773",
"references": [
{
"url": "https://git.kernel.org/stable/c/159360a0de831845c4500b4f8638decdcd624040",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1674855a5b6eacfe35f4db3095d7055c25467274",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/181012b3d29c51197c235ee5871fc7512c736855",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/259db2c04586d40b82c5c3002b1e28b0698a0bb7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/66238e2a74eca5dabf85b0cd2c3c944e474dc2fd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5e4d6cb4f6848b8906c1c493f99a8ccc0638515",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e6de568d3eda3e3c01c868fabd7a9535d5ee4a73",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f68038c77a2f38c09c7e2e4f7fa1f4e246fdf2c9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: atomically update mac addresses\n\nWhen a MAC address is updated in batadv_dat_entry_add(), it is done using a\nsimple copy function. A parallel reader might only see parts of this\nupdate. In worst case, the reader is transporting the half updated MAC\naddress over the network or is creating an ARP response using it -\npoisoning the ARP cache.\n\natomic64_t can be used to store the 48 bit of a mac address. A reader will\nthen either see the old mac address or the new one - never a mixture of\nboth."
}
],
"lastModified": "2026-10-03T11:17:46.550",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}