CVE-2026-52914: batman-adv: fix fragment reassembly length accounting
Published Jun 24, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
13 affected componentsFixes available
Linux kernel batman-adv
Linux Linux kernel>=3.13<5.10.258
Linux Linux kernel>=5.11<5.15.209
Linux Linux kernel>=5.16<6.1.175
Linux Linux kernel>=6.2<6.6.142
Linux Linux kernel>=6.7<6.12.92
Linux Linux kernel>=6.13<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
debian/linux
6.1.176-16.1.187-16.12.94-16.12.107-17.1.12-17.1.13-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1
Event History
Jun 24, 2026
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 13, 2026
Data Sourced
via Launchpad·08:41 PM
Description
Sep 7, 2026
Data Sourced
via Ubuntu·07:07 PM
RemedyDescriptionSeverityAffected Software
Sep 8, 2026
Data Sourced
via Debian·07:10 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-52914?
CVE-2026-52914 has a severity rating of 9.8, indicating it is critical.
2
How do I fix CVE-2026-52914?
The vulnerability CVE-2026-52914 can be fixed by applying the available patch.
3
What software is affected by CVE-2026-52914?
CVE-2026-52914 affects the Linux kernel and the batman-adv module.
4
What impact does CVE-2026-52914 have on my system?
CVE-2026-52914 may allow attackers to exploit fragment reassembly length accounting issues, potentially compromising the integrity and availability of the system.
5
When was CVE-2026-52914 published?
CVE-2026-52914 was published on June 24, 2026.