CVE-2026-52914 Details
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it to validate a fragment chain before reassembly. That accounting currently allows the accumulated fragment length to be truncated during updates. As a result, malformed fragment chains can bypass the intended validation and drive reassembly with inconsistent length state, leading to a local denial of service. Fix the accounting by storing the accumulated length in a length-typed field and rejecting update overflows before the existing validation logic runs. The fix was verified against the original reproducer and against valid fragment reassembly paths.
A denial-of-service vulnerability has been identified in the Linux kernel's batman-adv module. This issue arises from improper length accounting of fragmented packets, which can be exploited to create malformed fragment chains that bypass validation checks. The vulnerability allows for reassembly of fragments with inconsistent length information, causing disruption in the normal operation of the network protocol.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability. Instructions for downloading the patched version can be found in the Linux kernel Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/37be61825b15534a16ff9cfc9546de155b6df982 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3eb8bcb823391bd58997831b3c9c152a4ba8e255 | kernel.org | Patch |
| https://git.kernel.org/stable/c/975563c5de1123dde1ec7946bf5556d20c89d74e | kernel.org | Patch |
| https://git.kernel.org/stable/c/9cd3f16c320bfdadd4509358122368deb56a5741 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e4f3f6b818aa6a678bc54a2d4e0bece2303c6a64 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e910dbf509125fe51ad68e4fa74dc8ab0a8e787a | kernel.org | Patch |
| https://git.kernel.org/stable/c/f653b040dad1af70fa5cd4fe085e4758925480c9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fdb2c96efb2baeb3725e9ce3ede8f1e36f5490f0 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.13, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |