cbcvebase.
CVE-2026-31657
published 2026-04-24

CVE-2026-31657: In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace…

PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.6th percentile
In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow the pointer. The netlink claim dump path dereferences claim->backbone_gw->orig and takes claim->backbone_gw->crc_lock without pinning the underlying backbone gateway. batadv_bla_check_claim() still has the same naked pointer access pattern. Reuse batadv_bla_claim_get_backbone_gw() in both readers so they operate on a stable gateway reference until the read-side work is complete. This keeps the dump and claim-check paths aligned with the lifetime rules introduced for the other BLA claim readers.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 5202f071b367ffbc8e279fc7a00db14f5e587f525202f071b367ffbc8e279fc7a00db14f5e587f52
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 69d1ce9c72eca91203ffdb8d08bacd511100aec669d1ce9c72eca91203ffdb8d08bacd511100aec6
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < f4858832ddef2f39f21e30b7226bbcd3c4b2bc96f4858832ddef2f39f21e30b7226bbcd3c4b2bc96
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 2f55b58b5a0bbed192d60c444a45a49cdf1b545f2f55b58b5a0bbed192d60c444a45a49cdf1b545f
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 7962b522222628596ca9ecc8722efc95367aadbd7962b522222628596ca9ecc8722efc95367aadbd
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 4dee4c0688443aaf5bbec74aa203c851d1d53c354dee4c0688443aaf5bbec74aa203c851d1d53c35
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 1f2dc36c297d27733f1b380ea644cf15a361bd7b1f2dc36c297d27733f1b380ea644cf15a361bd7b
linuxlinux>= 23721387c409087fd3b97e274f34d3ddc0970b74 < 82d8701b2c930d0e96b0dbc9115a218d791cb0d282d8701b2c930d0e96b0dbc9115a218d791cb0d2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 3.5.1 < 6.1.1696.1.169
linuxlinux_kernel>= 6.13 < 6.18.236.18.23
linuxlinux_kernel>= 6.19 < 6.19.136.19.13
linuxlinux_kernel>= 6.2 < 6.6.1356.6.135
linuxlinux_kernel>= 6.7 < 6.12.826.12.82
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.