{"id":"CVE-2026-64090","summary":"batman-adv: tt: avoid empty VLAN responses","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: avoid empty VLAN responses\n\nThe commit 16116dac2339 (\"batman-adv: prevent TT request storms by not\nsending inconsistent TT TLVLs\") added checks to the local (direct) TT\nresponse code. But the response can also be done indirectly by another node\nusing the global TT state. To avoid such inconsistency states reported in\nthe original fix, also avoid sending empty VLANs for replies from the\nglobal TT state.","modified":"2026-07-21T03:47:53.374424863Z","published":"2026-07-19T15:39:59.392Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64090.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1f467d9a095211d3f77e8ff1bee90e73ffe01c64"},{"type":"WEB","url":"https://git.kernel.org/stable/c/99f17d1cdb371cbd037975239b321f346d38f6d2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9a02c8fc963ddeecb5d8788be0740c1869fc54b7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ab26e346322648f5c39de017d9723c9256284fce"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b93ca6012712ecab2b551e120d7c95038d6a89e5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cfb30645280a2131e46cbd1b9a38cfd3ff893f12"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ea4f757641430bcc8322772e161453c4db5ecb64"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fa1bd704940b5bcbc32c0b28db9167405c8ee5e0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64090.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64090"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b"},{"fixed":"1f467d9a095211d3f77e8ff1bee90e73ffe01c64"},{"fixed":"9a02c8fc963ddeecb5d8788be0740c1869fc54b7"},{"fixed":"ea4f757641430bcc8322772e161453c4db5ecb64"},{"fixed":"99f17d1cdb371cbd037975239b321f346d38f6d2"},{"fixed":"cfb30645280a2131e46cbd1b9a38cfd3ff893f12"},{"fixed":"b93ca6012712ecab2b551e120d7c95038d6a89e5"},{"fixed":"ab26e346322648f5c39de017d9723c9256284fce"},{"fixed":"fa1bd704940b5bcbc32c0b28db9167405c8ee5e0"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64090.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.13.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64090.json"}}],"schema_version":"1.7.5"}