cbcvebase.
CVE-2026-52931
published 2026-06-24

CVE-2026-52931: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and…

PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.5th percentile
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the BATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it proceeds to read sender-only members that were never initialized, leading to undefined behavior. This can be triggered when a node that is currently acting as a receiver in an ongoing tp_meter session receives a malicious ACK packet. Guard against this by checking tp_vars->role immediately after the lookup and bailing out if it is not BATADV_TP_SENDER, before any of those members are accessed.

Affected

20 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 0e388af04b3958b178a1b979527f93eb46ea1fee0e388af04b3958b178a1b979527f93eb46ea1fee
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 1a21c055f66e78973712a4a1be2a554f1ee2e4f41a21c055f66e78973712a4a1be2a554f1ee2e4f4
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 9884c9c02d3c90e9215db3c5128f59045d20ae919884c9c02d3c90e9215db3c5128f59045d20ae91
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 53f931e0146ae5bdab4cba302646827d06b3794b53f931e0146ae5bdab4cba302646827d06b3794b
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < ecdaa3e4d91040206afe21bc8a0d1198a0971ff3ecdaa3e4d91040206afe21bc8a0d1198a0971ff3
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < dc2ae5fbd2dadc26735092f140b246841d969a11dc2ae5fbd2dadc26735092f140b246841d969a11
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 85397e48afe6be83ffca5ad3f4792296bfc81d3d85397e48afe6be83ffca5ad3f4792296bfc81d3d
linuxlinux>= 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 6c65cf23d4c6170fcf5714c32aa64689718cb1426c65cf23d4c6170fcf5714c32aa64689718cb142
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.8 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.346.18.34
linuxlinux_kernel>= 6.19 < 7.0.117.0.11
linuxlinux_kernel>= 6.2 < 6.6.1426.6.142
linuxlinux_kernel>= 6.7 < 6.12.926.12.92
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.