CVE-2026-93203 — Kernel
HIGHCVE-2026-93203 is a high-severity (CVSS 7.1) vulnerability in Kernel. A fix is available for Kernel — see the affected versions and patch details below.
batman-adv: bla: avoid CRC corruption due to parallel claim add
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
CVE-2026-93203 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 374,847 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
KernelReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Linux packages — download data is not available via public APIs for these ecosystems.
Description
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: bla: avoid CRC corruption due to parallel claim add
batadv_bla_add_claim() is used to add claims and modify the backbone of claims for CLAIM frames from remote backbones and local packets. When it handles a claim, it needs to either
- add the new claim's CRC to the backbone CRC
- remove the already existing claim's CRC from the old backbone and add it to the new backbone
But when the "new" claim code was running in parallel to the "change backbone" code, it can happen that the CRC was invalid because the backbone_gw of the claim was changed twice in the "new" claim code path:
-
CPU0 creates the claim for gateway A and publishes it in the claim hash. The crc16 of the address has not yet been added to A's crc at this point.
-
CPU1 processes a claim frame of gateway B for the same client, finds the just published claim, and performs the ownership change: it switches the pointer to B, removes the crc16 from A's crc - which never contained it - and adds it to B's crc.
-
CPU0 continues behind the creation branch, unconditionally switches the pointer back to A without compensating B's crc (its remove_crc is false for the creation path), and finally adds the crc16 to A's crc
The CRC is then wrong for both:
- claim belongs to A: but CRC is not part of backbone A's CRC
- claim doesn't belong to B: CRC is still part of backbone B's CRC
This wrong CRC is never recomputated from the stored claims. For local backbone claims, this can also not recovered using syncs.
To avoid this, split the functionality in clear separate parts:
-
new claim which always adds claim CRC to the backbone CRC (but never changes the already set backbone_gw of the claim back)
-
update of existing claim which automatically changes the backbone_gw entry and only updates both backbone CRCs when there was an actual change
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐧Linux | Kernel | ≥ 3.5.0&&< 5.10.270 | 5.10.270 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for Kernel, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update Kernel to 5.10.270 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-93203 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2026-93203 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2026-93203. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-93203 in your dependencies?
O3 Security finds CVE-2026-93203 across Linux dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.