PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93204 Linux CVE debrief

The Linux kernel has a vulnerability in the batman-adv module where updating a MAC address is not atomic, potentially leading to readers seeing partial updates. This could result in incorrect ARP responses or poisoning of the ARP cache. The issue arises from the use of a simple copy function to update MAC addresses in batadv_dat_entry_add(), which can cause readers to see half-updated MAC addresses. To address this, defenders should verify their Linux kernel versions and apply patches to ensure atomic updates of MAC addresses.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-10-03
Advisory published
2026-09-17
Advisory updated
2026-10-03

Who should care

Defenders responsible for Linux kernel maintenance, network administrators, and security teams should assess exposure and prioritize patching. They should verify Linux kernel versions, review network configurations for batman-adv usage, and monitor for unusual ARP activity to mitigate potential impacts.

Why it matters

The Linux kernel vulnerability in batman-adv could lead to incorrect ARP responses or ARP cache poisoning if not patched, requiring defenders to verify and update their kernel versions.

  • Verify Linux kernel versions for potential vulnerability
  • Assess network configurations for batman-adv usage
  • Monitor for unusual ARP activity

Technical summary

The batman-adv module in the Linux kernel does not update MAC addresses atomically, potentially causing readers to see partial updates and leading to incorrect ARP responses or ARP cache poisoning. This issue can be addressed by using atomic64_t to store MAC addresses, ensuring that readers see either the old or new MAC address, but not a mixture of both. Defenders should prioritize verifying their Linux kernel versions and applying patches to address this vulnerability, particularly in environments where batman-adv is used.

Defensive priority

Defenders should prioritize verifying their Linux kernel versions and applying patches to address this vulnerability, particularly in environments where batman-adv is used.

Recommended defensive actions

  • Verify Linux kernel versions and apply patches for batman-adv module
  • Review network configurations for potential exposure
  • Monitor for unusual ARP activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but specific affected versions and exploitation details are not provided. Defenders should verify Linux kernel versions, review network configurations for batman-adv usage, and monitor for unusual ARP activity. The CVE record was published on 2026-09-17T17:18:16.773Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93204 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93204

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93204 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93204

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/159360a0de831845c4500b4f8638decdcd624040

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1674855a5b6eacfe35f4db3095d7055c25467274

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/181012b3d29c51197c235ee5871fc7512c736855

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/259db2c04586d40b82c5c3002b1e28b0698a0bb7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/66238e2a74eca5dabf85b0cd2c3c944e474dc2fd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a5e4d6cb4f6848b8906c1c493f99a8ccc0638515

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e6de568d3eda3e3c01c868fabd7a9535d5ee4a73

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f68038c77a2f38c09c7e2e4f7fa1f4e246fdf2c9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.