cve-2026-64089

CRITICAL CVSS 9.8 opencve
Description

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_my_tt_response(), last_changeset_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but populates only a small portion of it with the collected changeset. All remaining bits are kept uninitialized. Using an u16 avoids this type confusion and ensures that no (negative) sign extension is performed in batadv_send_my_tt_response().

Timeline
Published
2026-07-19 16:17 UTC
Last Modified
2026-08-11
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H mitre
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H nvd
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H opencve
References

No references available.

Linked Vulnerabilities

{
  "advisories": [
    {
      "id": "USN-8575-1",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8575-1"
    },
    {
      "id": "USN-8576-1",
      "source": "usn",
      "title": "Linux kernel (NVIDIA Tegra) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8576-1"
    },
    {
      "id": "USN-8593-1",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8593-1"
    },
    {
      "id": "USN-8575-2",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8575-2"
    },
    {
      "id": "USN-8576-2",
      "source": "usn",
      "title": "Linux kernel (NVIDIA Tegra) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8576-2"
    },
    {
      "id": "USN-8575-3",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8575-3"
    },
    {
      "id": "USN-8603-1",
      "source": "usn",
      "title": "Linux kernel (Azure) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8603-1"
    },
    {
      "id": "USN-8610-1",
      "source": "usn",
      "title": "Linux kernel (Azure CVM) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8610-1"
    },
    {
      "id": "USN-8618-1",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8618-1"
    },
    {
      "id": "USN-8620-1",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8620-1"
    },
    {
      "id": "USN-8620-2",
      "source": "usn",
      "title": "Linux kernel (Azure FIPS) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8620-2"
    },
    {
      "id": "USN-8620-3",
      "source": "usn",
      "title": "Linux kernel (Intel IoTG) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8620-3"
    },
    {
      "id": "USN-8620-4",
      "source": "usn",
      "title": "Linux kernel (Intel IoTG) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8620-4"
    },
    {
      "id": "USN-8663-1",
      "source": "usn",
      "title": "Linux kernel (NVIDIA) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8663-1"
    },
    {
      "id": "USN-8664-1",
      "source": "usn",
      "title": "Linux kernel (NVIDIA BaseOS) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8664-1"
    },
    {
      "id": "USN-8668-1",
      "source": "usn",
      "title": "Linux kernel (GCP) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8668-1"
    },
    {
      "id": "USN-8728-1",
      "source": "usn",
      "title": "Linux kernel (GCP) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8728-1"
    },
    {
      "id": "USN-8729-1",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8729-1"
    },
    {
      "id": "USN-8761-1",
      "source": "usn",
      "title": "Linux kernel (Azure) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8761-1"
    },
    {
      "id": "USN-8729-2",
      "source": "usn",
      "title": "Linux kernel (Raspberry Pi Real-time) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8729-2"
    },
    {
      "id": "USN-8761-2",
      "source": "usn",
      "title": "Linux kernel (Azure FIPS) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8761-2"
    },
    {
      "id": "USN-8781-1",
      "source": "usn",
      "title": "Linux kernel (NVIDIA Tegra) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8781-1"
    },
    {
      "id": "USN-8668-2",
      "source": "usn",
      "title": "Linux kernel (Raspberry Pi) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8668-2"
    },
    {
      "id": "USN-8729-3",
      "source": "usn",
      "title": "Linux kernel vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8729-3"
    },
    {
      "id": "USN-8802-1",
      "source": "usn",
      "title": "Linux kernel (Oracle) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8802-1"
    },
    {
      "id": "USN-8728-2",
      "source": "usn",
      "title": "Linux kernel (Azure) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8728-2"
    },
    {
      "id": "USN-8729-4",
      "source": "usn",
      "title": "Linux kernel (Low Latency) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8729-4"
    },
    {
      "id": "USN-8729-5",
      "source": "usn",
      "title": "Linux kernel (AWS FIPS) vulnerabilities",
      "url": "https://ubuntu.com/security/notices/USN-8729-5"
    }
  ],
  "cve": "CVE-2026-64089",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,6314089acf0ddf64376fdc0b1420695504c73f52)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,55dc41fe8821e9a849e147255ad572bc933a9d15)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,c424e8519ac78eac5d9f4eecf06208a0d619ec14)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,22d59c72f4a47ffec121d0610f70d0d70c3c11c8)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,eb235472b52ef36981c5aad330485eaf2382c53b)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,179eb62506a02d00370bd6478898cb632e10986c)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,d29abf70c665730e249d2ec8e1402095ae26bcee)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "code_commit",
              "value": "[a73105b8d4c765d9ebfb664d0a66802127d8e4c7,fc92cdfcb295cefa4344d71a527d61b638b7bfc4)"
            }
          }
        ],
        "enrichment": {
          "confidence": 99.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 99.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Linux",
          "source": "cna",
          "vendor": "Linux"
        },
        "product": "linux_kernel",
        "vendor": "linux"
      },
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "3.1"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "generic",
              "value": "[0,3.1)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[5.10.258,5.11.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[5.15.209,5.16.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[6.1.175,6.2.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[6.6.142,6.7.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[6.12.92,6.13.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[6.18.34,6.19.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "[7.0.11,7.1.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "generic",
              "value": "[7.1,*]"
            }
          }
        ],
        "enrichment": {
          "confidence": 99.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 99.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Linux",
          "source": "cna",
          "vendor": "Linux"
        },
        "product": "linux_kernel",
        "vendor": "linux"
      }
    ],
    "created": "2026-07-22T03:30:12.135783+00:00",
    "title": "batman‑adv Sign Extension Causes Uninitialized Buffer Allocation",
    "updated": "2026-08-13T13:15:04.111083+00:00",
    "vendors": [
      "linux",
      "linux$PRODUCT$linux_kernel"
    ]
  },
  "epss": {
    "score": 0.00755
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-07-19T15:39:58.729000+00:00",
    "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative last_changeset_len\n\nbatadv_piv_tt::last_changeset_len len was declared as s16, but the field is\nnever intended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_my_tt_response(), last_changeset_len is temporarily widened\nto s32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_my_tt_response().",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/64xxx/CVE-2026-64089.json",
    "references": [
      "https://git.kernel.org/stable/c/179eb62506a02d00370bd6478898cb632e10986c",
      "https://git.kernel.org/stable/c/22d59c72f4a47ffec121d0610f70d0d70c3c11c8",
      "https://git.kernel.org/stable/c/55dc41fe8821e9a849e147255ad572bc933a9d15",
      "https://git.kernel.org/stable/c/6314089acf0ddf64376fdc0b1420695504c73f52",
      "https://git.kernel.org/stable/c/c424e8519ac78eac5d9f4eecf06208a0d619ec14",
      "https://git.kernel.org/stable/c/d29abf70c665730e249d2ec8e1402095ae26bcee",
      "https://git.kernel.org/stable/c/eb235472b52ef36981c5aad330485eaf2382c53b",
      "https://git.kernel.org/stable/c/fc92cdfcb295cefa4344d71a527d61b638b7bfc4"
    ],
    "title": "batman-adv: tt: fix negative last_changeset_len",
    "updated": "2026-08-05T12:39:06.132000+00:00",
    "vendors": [
      "linux",
      "linux$PRODUCT$linux_kernel"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
      "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
      "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
      "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*"
    ],
    "created": "2026-07-19T16:17:49.697000+00:00",
    "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative last_changeset_len\n\nbatadv_piv_tt::last_changeset_len len was declared as s16, but the field is\nnever intended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_my_tt_response(), last_changeset_len is temporarily widened\nto s32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_my_tt_response().",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-64089.json",
    "references": [
      "https://git.kernel.org/stable/c/179eb62506a02d00370bd6478898cb632e10986c",
      "https://git.kernel.org/stable/c/22d59c72f4a47ffec121d0610f70d0d70c3c11c8",
      "https://git.kernel.org/stable/c/55dc41fe8821e9a849e147255ad572bc933a9d15",
      "https://git.kernel.org/stable/c/6314089acf0ddf64376fdc0b1420695504c73f52",
      "https://git.kernel.org/stable/c/c424e8519ac78eac5d9f4eecf06208a0d619ec14",
      "https://git.kernel.org/stable/c/d29abf70c665730e249d2ec8e1402095ae26bcee",
      "https://git.kernel.org/stable/c/eb235472b52ef36981c5aad330485eaf2382c53b",
      "https://git.kernel.org/stable/c/fc92cdfcb295cefa4344d71a527d61b638b7bfc4"
    ],
    "title": null,
    "updated": "2026-08-11T15:33:55.310000+00:00",
    "vendors": [
      "linux",
      "linux$PRODUCT$linux_kernel"
    ],
    "weaknesses": [
      "NVD-CWE-noinfo"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-07-19T16:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative last_changeset_len\n\nbatadv_piv_tt::last_changeset_len len was declared as s16, but the field is\nnever intended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_my_tt_response(), last_changeset_len is temporarily widened\nto s32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_my_tt_response().",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "batman-adv: tt: fix negative last_changeset_len",
              "old": null
            },
            "type": "title"
          },
          {
            "details": [
              "linux",
              "linux$PRODUCT$linux_kernel"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "linux",
                "linux$PRODUCT$linux_kernel"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://git.kernel.org/stable/c/179eb62506a02d00370bd6478898cb632e10986c",
                "https://git.kernel.org/stable/c/22d59c72f4a47ffec121d0610f70d0d70c3c11c8",
                "https://git.kernel.org/stable/c/55dc41fe8821e9a849e147255ad572bc933a9d15",
                "https://git.kernel.org/stable/c/6314089acf0ddf64376fdc0b1420695504c73f52",
                "https://git.kernel.org/stable/c/c424e8519ac78eac5d9f4eecf06208a0d619ec14",
                "https://git.kernel.org/stable/c/d29abf70c665730e249d2ec8e1402095ae26bcee",
                "https://git.kernel.org/stable/c/eb235472b52ef36981c5aad330485eaf2382c53b",
                "https://git.kernel.org/stable/c/fc92cdfcb295cefa4344d71a527d61b638b7bfc4"
              ],
              "removed": []
            },
            "type": "references"
          }
        ],
        "id": "20c18834-a849-4609-a9fd-7fbda8d506bb"
      },
      {
        "created": "2026-07-20T12:15:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-190"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://lore.kernel.org/linux-cve-announce/2026071917-CVE-2026-64089-321e@gregkh/T",
                "https://nvd.nist.gov/vuln/detail/CVE-2026-64089",
                "https://www.cve.org/CVERecord?id=CVE-2026-64089"
              ],
              "removed": []
            },
            "type": "references"
          }
        ],
        "id": "be9ae738-599b-469d-b4cf-5c2a819b1366"
      },
      {
        "created": "2026-07-20T14:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 9.8,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "7ba3ac8d-5b54-4c37-9aa5-74ea11661985"
      },
      {
        "created": "2026-08-11T16:00:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "NVD-CWE-noinfo"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          }
        ],
        "id": "b72ec99c-30f9-4d4e-bb4c-739c0e8c2537"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
        "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
        "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
        "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-07-19T00:00:00+00:00",
      "provider": "redhat"
    },
    "description": {
      "data": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative last_changeset_len\n\nbatadv_piv_tt::last_changeset_len len was declared as s16, but the field is\nnever intended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_my_tt_response(), last_changeset_len is temporarily widened\nto s32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_my_tt_response().",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 9.8,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00755
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {},
        "provider": null
      },
      "threat_severity": {
        "data": null,
        "provider": "redhat"
      }
    },
    "references": {
      "data": [
        "https://git.kernel.org/stable/c/179eb62506a02d00370bd6478898cb632e10986c",
        "https://git.kernel.org/stable/c/22d59c72f4a47ffec121d0610f70d0d70c3c11c8",
        "https://git.kernel.org/stable/c/55dc41fe8821e9a849e147255ad572bc933a9d15",
        "https://git.kernel.org/stable/c/6314089acf0ddf64376fdc0b1420695504c73f52",
        "https://git.kernel.org/stable/c/c424e8519ac78eac5d9f4eecf06208a0d619ec14",
        "https://git.kernel.org/stable/c/d29abf70c665730e249d2ec8e1402095ae26bcee",
        "https://git.kernel.org/stable/c/eb235472b52ef36981c5aad330485eaf2382c53b",
        "https://git.kernel.org/stable/c/fc92cdfcb295cefa4344d71a527d61b638b7bfc4",
        "https://lore.kernel.org/linux-cve-announce/2026071917-CVE-2026-64089-321e@gregkh/T",
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64089",
        "https://www.cve.org/CVERecord?id=CVE-2026-64089"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    },
    "title": {
      "data": "batman-adv: tt: fix negative last_changeset_len",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-08-11T15:33:55.310000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "linux",
        "linux$PRODUCT$linux_kernel"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-190",
        "NVD-CWE-noinfo"
      ],
      "providers": [
        "nvd",
        "redhat"
      ]
    }
  },
  "redhat": {
    "cpes": [],
    "created": "2026-07-19T00:00:00+00:00",
    "description": "A flaw was found in the Linux kernel's batman-adv module. An integer overflow vulnerability in the last_changeset_len field can cause it to become a negative value. This leads to a buffer being improperly initialized, potentially exposing sensitive information. A local attacker could exploit this to achieve information disclosure.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "threat_severity": null
    },
    "redhat_repo_path": "2026/CVE-2026-64089.json",
    "references": [
      "https://lore.kernel.org/linux-cve-announce/2026071917-CVE-2026-64089-321e@gregkh/T",
      "https://nvd.nist.gov/vuln/detail/CVE-2026-64089",
      "https://www.cve.org/CVERecord?id=CVE-2026-64089"
    ],
    "title": "kernel: batman-adv: tt: fix negative last_changeset_len",
    "updated": "2026-07-19T00:00:00+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-190"
    ]
  }
}
Enrichment data
View JSON API Download JSON