Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72231— batman-adv: tt: avoid request storms during pending request

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于batman-adv的batadv_send_tt_request函数在发送缓冲区分配失败后清理TT请求时条件判断错误,可能导致请求风暴。

CVSS 7.5 · High EPSS 0.69% · P50

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 6055695ea40c64a47e00742c12c99b1a33b4daed affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 21c44a6895f41df811d1c91d10eea194dda2b345 affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 5e46c76d9a5062212c4c5f642a5549fd9c057f8a affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 067e413eec2e63c2996909ef55214b3a0eda0be7 affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 716f434eb35869e130424331584a91fbb729b9bd affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 6a65ac8a81e903bb4b555c1d13532f5cb0167a4a affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< aba1cf21954e64c36afb966b754adad2b0b8aa48 affected
335fbe0f5d2501b7dd815806aef6fd9bad784eb1< 27c7d40008231ae4140d35501b60087a9de2d2c3 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72231

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
batman-adv: tt: avoid request storms during pending request
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid request storms during pending request batadv_send_tt_request() allocates a tt_req_node when none exists for the destination originator node. This should prevent that a multiple TT requests are send at the same time to an originator. But if allocation of the send buffer failed, this request must be cleaned up again. But indicator for such a failure is "ret == false". But the actual implementation is checking for "ret == true". The check must be inverted to not loose the information about the TT request directly after it was attempted to be sent out. This should avoid potential request storms.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于batman-adv的batadv_send_tt_request函数在发送缓冲区分配失败后清理TT请求时条件判断错误,可能导致请求风暴。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 335fbe0f5d2501b7dd815806aef6fd9bad784eb1 ~ 6055695ea40c64a47e00742c12c99b1a33b4daed -
Linux Linux 3.13 -

II. Public POCs for CVE-2026-72231

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72231

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72231 (8)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-74376 9.8 CRITICAL md/raid10: reset read_slot when reusing r10bio for discard
CVE-2026-74433 9.8 CRITICAL rxrpc: Fix UAF in rxgk_issue_challenge()
CVE-2026-74434 9.8 CRITICAL rxrpc: Don't move a peeked OOB message onto the pending queue
CVE-2026-72191 9.8 CRITICAL ntfs3: validate split-point offset in indx_insert_into_buffer
CVE-2026-72299 9.8 CRITICAL tipc: restrict socket queue dumps in enqueue tracepoints
CVE-2026-72398 9.8 CRITICAL sctp: add INIT verification after cookie unpacking
CVE-2026-74384 9.8 CRITICAL nvme-multipath: fix flex array size in struct nvme_ns_head
CVE-2026-72442 9.8 CRITICAL netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
CVE-2026-74436 9.8 CRITICAL rxrpc: serialize kernel accept preallocation with socket teardown
CVE-2026-74545 9.8 CRITICAL rtase: fix double free of multi-frag skb on DMA map failure
CVE-2026-72046 9.8 CRITICAL gve: fix header buffer corruption with header-split and HW-GRO
CVE-2026-72473 9.8 CRITICAL xprtrdma: Decouple req recycling from RPC completion

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72231

No comments yet


Leave a comment