Linux Kernel Vulnerability in Batman-adv Component
CVE-2026-63834

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63834?

A vulnerability in the Linux kernel's batman-adv component allows attackers to exploit unacked_list behaviors by sending specially crafted messages. This can induce excessive memory allocation for unacked_list entries, potentially leading to resource exhaustion or increased CPU overhead as the system struggles to manage an expanding list. To mitigate this risk, it is crucial to implement strict limits on the list's size while ensuring that the management process can continue unimpeded by dropping the least significant entries when necessary.

Affected Version(s)

Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 31a88792bfba142be3c9521538c1db805677381f

Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 1111a3381bca2d1f084a07686bc783af5ab23df7

Linux 33a3bb4a3345bb511f9c69c913da95d4693e2a4e < 1c616b0be4bd8399d485e25e91859373b95d6013

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.