Back to overview

CVE-2026-52931

Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the BATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it proceeds to read sender-only members that were never initialized, leading to undefined behavior. This can be triggered when a node that is currently acting as a receiver in an ongoing tp_meter session receives a malicious ACK packet. Guard against this by checking tp_vars->role immediately after the lookup and bailing out if it is not BATADV_TP_SENDER, before any of those members are accessed.

Metadata

CVE ID
CVE-2026-52931
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 07:14 UTC
Last updated
2026-06-24 07:14 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 0e388af04b3958b178a1b979527f93eb46ea1fee, 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 1a21c055f66e78973712a4a1be2a554f1ee2e4f4, 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 9884c9c02d3c90e9215db3c5128f59045d20ae91, 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 53f931e0146ae5bdab4cba302646827d06b3794b …
Linux Linux 4.8, 0 < 4.8, 5.10.258 ≤ 5.10.*, 5.15.209 ≤ 5.15.* …
Back to overview