cbcvebase.
CVE-2026-31659
published 2026-04-24

CVE-2026-31659: In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers…

PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.5th percentile
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_global_data() builds the allocation length for a global TT response in 16-bit temporaries. When a remote originator advertises a large enough global TT, the TT payload length plus the VLAN header offset can exceed 65535 and wrap before kmalloc(). The full-table response path still uses the original TT payload length when it fills tt_change, so the wrapped allocation is too small and batadv_tt_prepare_tvlv_global_data() writes past the end of the heap object before the later packet-size check runs. Fix this by rejecting TT responses whose TVLV value length cannot fit in the 16-bit TVLV payload length field.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < 7e5d007e0df946bffb8542fb112e0044014a58977e5d007e0df946bffb8542fb112e0044014a5897
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < 2997f4bd1f982e7013709946e00be89b507693fa2997f4bd1f982e7013709946e00be89b507693fa
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < 95c71365a2222908441b54d6f2c315e0c79fcec395c71365a2222908441b54d6f2c315e0c79fcec3
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < 69d61639bc7e963c3b645e570279d731e7c8906269d61639bc7e963c3b645e570279d731e7c89062
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < f970646b9a39539d1bac86822ac78b5915455ea9f970646b9a39539d1bac86822ac78b5915455ea9
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < de6c1dc3c7d01a152607e6fcecee4d5288283f10de6c1dc3c7d01a152607e6fcecee4d5288283f10
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < cf2199171ef799ca7270019125f4a91bd20ad4d9cf2199171ef799ca7270019125f4a91bd20ad4d9
linuxlinux>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b < 3a359bf5c61d52e7f09754108309d637532164a63a359bf5c61d52e7f09754108309d637532164a6
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 3.13.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1696.1.169
linuxlinux_kernel>= 6.13 < 6.18.236.18.23
linuxlinux_kernel>= 6.19 < 6.19.136.19.13
linuxlinux_kernel>= 6.2 < 6.6.1356.6.135
linuxlinux_kernel>= 6.7 < 6.12.826.12.82
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-4.15

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.