Linux Kernel Vulnerability in Batman-adv Component
CVE-2026-63834
What is CVE-2026-63834?
A vulnerability in the Linux kernel's batman-adv component allows attackers to exploit unacked_list behaviors by sending specially crafted messages. This can induce excessive memory allocation for unacked_list entries, potentially leading to resource exhaustion or increased CPU overhead as the system struggles to manage an expanding list. To mitigate this risk, it is crucial to implement strict limits on the list's size while ensuring that the management process can continue unimpeded by dropping the least significant entries when necessary.
Affected Version(s)
Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 31a88792bfba142be3c9521538c1db805677381f
Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 1111a3381bca2d1f084a07686bc783af5ab23df7
Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 1c616b0be4bd8399d485e25e91859373b95d6013