CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's batman-adv module, specifically in the handling of stale backbone gateway entries during the purge process. Improper management of the report_work associated with these entries can lead to use-after-free conditions, potentially allowing an attacker to execute arbitrary code or crash the system. Organizations utilizing Linux systems with batman-adv should prioritize patching this vulnerability to mitigate the risk of exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their associated report_work: - If report_work is running, the purge must wait for it to finish before freeing the backbone_gw, otherwise the worker may access freed memory (e.g. bat_priv). - If report_work is pending, the purge must cancel it and release the reference held for that pending work item. The previous implementation called hlist_for_each_entry_safe() inside a spin_lock_bh() section, but cancel_work_sync() may sleep and therefore cannot be called from within a spinlock-protected region. Restructure the loop to handle one entry per spinlock critical section: acquire the lock, find the next entry to purge, remove it from the hash list, then release the lock before calling cancel_work_sync() and dropping the hash_entry reference. Repeat until no more entries require purging.
Related CVEs
Other vulnerabilities affecting the same vendor(s)