CVE-2026-52914: batman-adv: fix fragment reassembly length accounting
Published Jun 24, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
14 affected componentsFixes available
Linux kernel batman-adv
Linux Linux kernel>=3.13<5.10.258
Linux Linux kernel>=5.11<5.15.209
Linux Linux kernel>=5.16<6.1.175
Linux Linux kernel>=6.2<6.6.142
Linux Linux kernel>=6.7<6.12.92
Linux Linux kernel>=6.13<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
debian/linux<=5.10.223-1
5.10.262-16.1.176-16.1.180-16.12.94-16.12.101-17.1.7-17.1.8-1
debian/linux-6.1
6.1.180-1~deb11u1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.180-1~deb11u1
Event History
Jun 24, 2026
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 12, 2026
Data Sourced
via Debian·08:40 PM
DescriptionAffected Software
Aug 13, 2026
Data Sourced
via Launchpad·08:41 PM
Description
Aug 14, 2026
Data Sourced
via Ubuntu·08:41 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-52914?
CVE-2026-52914 has a severity rating of 9.8, indicating it is critical.
2
How do I fix CVE-2026-52914?
The vulnerability CVE-2026-52914 can be fixed by applying the available patch.
3
What software is affected by CVE-2026-52914?
CVE-2026-52914 affects the Linux kernel and the batman-adv module.
4
What impact does CVE-2026-52914 have on my system?
CVE-2026-52914 may allow attackers to exploit fragment reassembly length accounting issues, potentially compromising the integrity and availability of the system.
5
When was CVE-2026-52914 published?
CVE-2026-52914 was published on June 24, 2026.