CVE-2026-52914

Updated on 24 Jun 2026

Severity

9.8 Critical severity

Details

CVSS score
9.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: fix fragment reassembly length accounting

batman-adv keeps a running payload length for queued fragments and uses it to validate a fragment chain before reassembly.

That accounting currently allows the accumulated fragment length to be truncated during updates. As a result, malformed fragment chains can bypass the intended validation and drive reassembly with inconsistent length state, leading to a local denial of service.

Fix the accounting by storing the accumulated length in a length-typed field and rejecting update overflows before the existing validation logic runs.

The fix was verified against the original reproducer and against valid fragment reassembly paths.

Details

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 11 Planned
Debian 11 cloud Planned
Debian 12 Planned
Ubuntu 16.04 AWS HWE ESM Planned
Ubuntu 16.04 HWE ESM Planned
Ubuntu 18.04 Planned
Ubuntu 20.04 Planned
Ubuntu 22.04 Planned
Ubuntu 24.04 Planned
Ubuntu 24.04 AWS Planned