๐Ÿ” CVE Alert

CVE-2026-52934

UNKNOWN 0.0

batman-adv: tvlv: reject oversized TVLV packets

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_append() builds a TVLV packet section from the tvlv.container_list. The total size of this section is computed by batadv_tvlv_container_list_size(), which sums the sizes of all registered containers. The return type and accumulator in batadv_tvlv_container_list_size() were u16. If the accumulated size exceeds U16_MAX, the value wraps around, causing the subsequent allocation in batadv_tvlv_container_ogm_append() to be undersized. The memcpy-style copy that follows would then write beyond the end of the allocated buffer, corrupting kernel memory. Fix this by widening the return type of batadv_tvlv_container_list_size() to size_t. In batadv_tvlv_container_ogm_append(), check the computed length against U16_MAX before proceeding, and bail out as if the allocation had failed when the limit is exceeded.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ef26157747d42254453f6b3ac2bd8bd3c53339c3 < c02aa6c0c9d1bea9bb75dea362b75ad225137bae ef26157747d42254453f6b3ac2bd8bd3c53339c3 < 1595628a2f877d052eda18865ccf539392c47c04 ef26157747d42254453f6b3ac2bd8bd3c53339c3 < 6448a49344e87487b61bd88cb850cd694a0f576d ef26157747d42254453f6b3ac2bd8bd3c53339c3 < 13493b00dd1e05a705981e052158652ea23eb482 ef26157747d42254453f6b3ac2bd8bd3c53339c3 < 94db72e9dac202e017ee3db22c59d17e4f3bf171 ef26157747d42254453f6b3ac2bd8bd3c53339c3 < ede47988ac5687793745b17c1634a496a2299919 ef26157747d42254453f6b3ac2bd8bd3c53339c3 < 94a3d72cd9b21116d7c6d5bdc57c11401fc28557 ef26157747d42254453f6b3ac2bd8bd3c53339c3 < f50487e3566358b2b982b7801945e858c78ad9ab
Linux / Linux
3.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c02aa6c0c9d1bea9bb75dea362b75ad225137bae git.kernel.org: https://git.kernel.org/stable/c/1595628a2f877d052eda18865ccf539392c47c04 git.kernel.org: https://git.kernel.org/stable/c/6448a49344e87487b61bd88cb850cd694a0f576d git.kernel.org: https://git.kernel.org/stable/c/13493b00dd1e05a705981e052158652ea23eb482 git.kernel.org: https://git.kernel.org/stable/c/94db72e9dac202e017ee3db22c59d17e4f3bf171 git.kernel.org: https://git.kernel.org/stable/c/ede47988ac5687793745b17c1634a496a2299919 git.kernel.org: https://git.kernel.org/stable/c/94a3d72cd9b21116d7c6d5bdc57c11401fc28557 git.kernel.org: https://git.kernel.org/stable/c/f50487e3566358b2b982b7801945e858c78ad9ab