Junglewise Threat Intelligence

CVE-2026-52934: Linux Kernel batman-adv heap overflow in TVLV packet handling

CVE-2026-52934 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's 'batman-adv' mesh networking protocol. This component is used to manage communication between devices in a decentralized network. An attacker could potentially send specially crafted network packets that cause the system to miscalculate memory requirements, leading to a system crash or unauthorized memory access. This could disrupt network operations or allow for further exploitation of the affected device.

Technical details

An integer overflow exists in the batadv_tvlv_container_list_size() function within the batman-adv mesh networking implementation. The function used a 16-bit unsigned integer (u16) to accumulate the total size of registered TVLV containers. If the combined size exceeds 65,535 bytes, the value wraps around, leading to an undersized memory allocation in batadv_tvlv_container_ogm_append(). Subsequent memcpy operations then write beyond the allocated buffer, resulting in kernel heap corruption. This can be triggered via network-reachable vectors if an attacker can influence the registration or processing of TVLV containers. The fix involves widening the accumulator to size_t and implementing explicit bounds checking against U16_MAX.

Affected products

  • Linux Linux Kernel ef26157747d4 to f50487e35663

Timeline

  • 2026-05-29: patched: Initial fix authored by Sven Eckelmann
  • 2026-06-24: disclosed: CVE published in NVD

References

Related threats