CVE-2026-52914
published 2026-06-24CVE-2026-52914: In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.52%
40.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: fix fragment reassembly length accounting
batman-adv keeps a running payload length for queued fragments and uses it
to validate a fragment chain before reassembly.
That accounting currently allows the accumulated fragment length to be
truncated during updates. As a result, malformed fragment chains can
bypass the intended validation and drive reassembly with inconsistent
length state, leading to a local denial of service.
Fix the accounting by storing the accumulated length in a length-typed
field and rejecting update overflows before the existing validation logic
runs.
The fix was verified against the original reproducer and against valid
fragment reassembly paths.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < e4f3f6b818aa6a678bc54a2d4e0bece2303c6a64 | e4f3f6b818aa6a678bc54a2d4e0bece2303c6a64 |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < 37be61825b15534a16ff9cfc9546de155b6df982 | 37be61825b15534a16ff9cfc9546de155b6df982 |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < 975563c5de1123dde1ec7946bf5556d20c89d74e | 975563c5de1123dde1ec7946bf5556d20c89d74e |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < f653b040dad1af70fa5cd4fe085e4758925480c9 | f653b040dad1af70fa5cd4fe085e4758925480c9 |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < e910dbf509125fe51ad68e4fa74dc8ab0a8e787a | e910dbf509125fe51ad68e4fa74dc8ab0a8e787a |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < 3eb8bcb823391bd58997831b3c9c152a4ba8e255 | 3eb8bcb823391bd58997831b3c9c152a4ba8e255 |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < fdb2c96efb2baeb3725e9ce3ede8f1e36f5490f0 | fdb2c96efb2baeb3725e9ce3ede8f1e36f5490f0 |
| linux | linux | >= 610bfc6bc99bc83680d190ebc69359a05fc7f605 < 9cd3f16c320bfdadd4509358122368deb56a5741 | 9cd3f16c320bfdadd4509358122368deb56a5741 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 3.13 < 5.10.258 | 5.10.258 |
| linux | linux_kernel | >= 5.11 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 6.13 < 6.18.34 | 6.18.34 |
| linux | linux_kernel | >= 6.19 < 7.0.11 | 7.0.11 |
| linux | linux_kernel | >= 6.2 < 6.6.142 | 6.6.142 |
| linux | linux_kernel | >= 6.7 < 6.12.92 | 6.12.92 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: batman-adv: fix fragment reassembly length accounting
vendor_redhat·2026-06-24
CVE-2026-52914 CWE-130 kernel: batman-adv: fix fragment reassembly length accounting
kernel: batman-adv: fix fragment reassembly length accounting
A flaw was found in the Linux kernel's batman-adv component. This vulnerability allows a local attacker to cause a denial of service (DoS) by sending malformed fragment chains. The flaw is due to incorrect accounting of fragment reassembly length, which can be truncated during updates, bypassing validation and leading to inconsistent length states during reassembly.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affe
GHSA
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it t
ghsa_unreviewed·2026-06-24
CVE-2026-52914 In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it t
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: fix fragment reassembly length accounting
batman-adv keeps a running payload length for queued fragments and uses it
to validate a fragment chain before reassembly.
That accounting currently allows the accumulated fragment length to be
truncated during updates. As a result, malformed fragment chains can
bypass the intended validation and drive reassembly with inconsistent
length state, leading to a local denial of service.
Fix the accounting by storing the accumulated length in a length-typed
field and rejecting update overflows before the existing validation logic
runs.
The fix was verified against the original reproducer and against valid
fragment reassembly paths.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/37be61825b15534a16ff9cfc9546de155b6df982https://git.kernel.org/stable/c/3eb8bcb823391bd58997831b3c9c152a4ba8e255https://git.kernel.org/stable/c/975563c5de1123dde1ec7946bf5556d20c89d74ehttps://git.kernel.org/stable/c/9cd3f16c320bfdadd4509358122368deb56a5741https://git.kernel.org/stable/c/e4f3f6b818aa6a678bc54a2d4e0bece2303c6a64https://git.kernel.org/stable/c/e910dbf509125fe51ad68e4fa74dc8ab0a8e787ahttps://git.kernel.org/stable/c/f653b040dad1af70fa5cd4fe085e4758925480c9https://git.kernel.org/stable/c/fdb2c96efb2baeb3725e9ce3ede8f1e36f5490f0
2026-06-24
Published