Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: frag: free unfragmentable packet

The caller of batadv_frag_send_packet() assume that the skb provided to the
function are always consumed. But the pre-check for an empty payload or the
zero fragment size returned an error without any further actions.

A failed pre-check must use the same error handling code as the rest of the
function.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The batadv_frag_send_packet function in the Linux kernel is expected to consume every skb passed to it, but a pre‑check for an empty payload or a zero fragment size returns an error without executing the function’s standard error handling path. This oversight allows a packet to be freed prematurely, resulting in a use‑after‑free condition that can corrupt kernel memory or trigger a crash. If an attacker can direct malformed traffic into the batman‑adv fragmentation routine, the flaw may provide a path to kernel compromise or privilege escalation. The vulnerability directly affects the batman‑adv networking module and is classified as a memory corruption weakness.

Affected Systems

This issue applies to the Linux kernel, specifically the batman‑adv mesh networking module. No particular kernel version is cited in the CNA data, so any distribution that includes the affected batman‑adv release is potentially vulnerable. Systems using an unmodified or outdated kernel build with batman‑adv present should verify that the fix has been incorporated.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is the injection of crafted network packets that trigger the mis‑handled fragmentation path on the targeted system or on a device acting as a batman‑adv relay. Successful exploitation could lead to kernel memory corruption, crashes, or arbitrary code execution, depending on the attacker’s level of control over the target environment.

Generated by OpenCVE AI on August 22, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the batman‑adv fragment bug fix.
  • If an immediate kernel update is not possible, unload or disable the batman‑adv module until a patched kernel is available.
  • Monitor system logs, kernel crash dumps, and network traffic for signs of abnormal panics or memory corruption related to batman‑adv packets and respond accordingly.

Generated by OpenCVE AI on August 22, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-459
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: free unfragmentable packet The caller of batadv_frag_send_packet() assume that the skb provided to the function are always consumed. But the pre-check for an empty payload or the zero fragment size returned an error without any further actions. A failed pre-check must use the same error handling code as the rest of the function.
Title batman-adv: frag: free unfragmentable packet
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:10:46.396Z

Reserved: 2026-08-09T03:40:39.913Z

Link: CVE-2026-72230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:49.870

Modified: 2026-08-17T06:18:24.257

Link: CVE-2026-72230

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72230 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T09:30:17Z

Weaknesses