CVE-2026-31657: batman-adv: hold claim backbone gateways by reference
Published Apr 24, 2026
·Updated
batman-adv: hold claim backbone gateways by reference
Affected Software
15 affected componentsFixes available
Linux batman-adv
Linux Linux kernel>=3.5.1<6.1.169
Linux Linux kernel>=6.2<6.6.135
Linux Linux kernel>=6.7<6.12.82
Linux Linux kernel>=6.13<6.18.23
Linux Linux kernel>=6.19<6.19.13
Linux Linux kernel=3.5
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Microsoft azl3 kernel 6.6.134.1-2
Event History
Apr 24, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 26, 2026
Data Sourced
via Microsoft·08:07 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:07 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-31657?
CVE-2026-31657 is classified as a medium-severity vulnerability due to potential memory corruption issues.
2
How do I fix CVE-2026-31657?
To mitigate CVE-2026-31657, ensure you update to the latest version of the batman-adv package in the Linux kernel.
3
What systems are affected by CVE-2026-31657?
CVE-2026-31657 affects the batman-adv module within various Linux kernel versions utilized in mesh networking.
4
What type of vulnerability is CVE-2026-31657?
CVE-2026-31657 is a memory management vulnerability that can lead to improper handling of backbone gateway references.
5
Who can exploit CVE-2026-31657?
CVE-2026-31657 can potentially be exploited by local attackers who have access to the network and can invoke the batman-adv functionalities.