CVE-2026-72226
CVE CVE-2026-72226EUVD EUVD-2026-59125Published 2026-08-15T05:54:18.000ZLast changed 2026-08-17T05:41:46.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB check overflow A TT unicast TVLV contains the number of VLANs stored in it. This number is an u16 and gets multiplied by the size of the struct batadv_tvlv_tt_vlan_data (8 bytes). The size can therefore overflow the u16 used to store the tt_vlan_len. All additional safety checks to prevent out-of-bounds access of the TVLV buffer are invalid due to this overflow. Using size_t prevents this overflow and ensures that the safety checks compare against the actual buffer requirements.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <3256c05d5a9db34346eaf20f52dddde984852d77; patch: 6.18.40; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <1898273c5dc8148267ef9f97cd2517a2822350e7; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <7319c0794f91be2734aac695794e7203606b49f8; patch: 7.2; 3.13; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <7a581d9aaba8c82bd6177fa36b2588eea77f6e2b; patch: 5.15.212; patch: 6.6.145; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <6222b443686525cb5a9b6a9cecf23b2e2ab23e2a; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <604bd5042fbcd1ab9f7cd98fd847ec017aeede8a; patch: 7.1.5; patch: 6.12.97; patch: 0; patch: 6.1.178; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <0de12a4c4847f571d82a9cd96bc633eded41d7c6; patch: 5.10.261; 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b <d6ff4764ff784ede25f5c83a6f5883a74c93a5ea
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.