Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: tt: avoid request storms during pending request

batadv_send_tt_request() allocates a tt_req_node when none exists for the
destination originator node. This should prevent that a multiple TT
requests are send at the same time to an originator.

But if allocation of the send buffer failed, this request must be cleaned
up again. But indicator for such a failure is "ret == false". But the
actual implementation is checking for "ret == true".

The check must be inverted to not loose the information about the TT
request directly after it was attempted to be sent out. This should avoid
potential request storms.
Published: 2026-08-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The batman‑adv module of the Linux kernel contains a logic error caused by an incorrect return value check during TT request buffer allocation. When the allocation fails, the code mistakenly interprets this as success, leaving stale TT requests persistent. This flaw represents a CWE‑772 weakness that can lead to uncontrolled resource consumption, specifically a storm of TT request traffic that floods the network and drains node resources. The resulting denial of service can affect all devices participating in the batman‑adv network, disrupting communication and potentially exhausting network bandwidth.

Affected Systems

All Linux kernel releases shipping the batman‑adv module without the recent patch are potentially affected. Because no specific version range is provided, any kernel that includes batman‑adv prior to the fix is vulnerable. This encompasses most current Linux distributions that use the standard kernel, as the module is a standard component of the Linux kernel kernel tree.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while an EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low likelihood of widespread exploitation. Based on the description, an attacker would need to trigger repeated TT request allocation failures, which could be achieved by flooding the node with malformed packets or through a local compromise that forces allocation failures. The likely attack vector is local or remote traffic manipulation within a batman‑adv network, though public exploits are not known. The low EPSS indicates that the vulnerability is currently considered low risk for exploitation, but the high impact warrants immediate patching if exposure is possible.

Generated by OpenCVE AI on August 18, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the batman‑adv patch correcting the allocation check.
  • If an upgrade cannot be performed immediately, unload or disable the batman‑adv module to stop TT request traffic from generating storms.
  • Configure the network to limit the rate of TT requests or suppress TT traffic on a per-node basis until the patch is applied.
  • Deploy monitoring to detect abnormal spikes in TT request traffic and alert administrators when thresholds are exceeded.

Generated by OpenCVE AI on August 18, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-571

Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-571

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-560
CWE-847

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 15 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-560
CWE-847

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid request storms during pending request batadv_send_tt_request() allocates a tt_req_node when none exists for the destination originator node. This should prevent that a multiple TT requests are send at the same time to an originator. But if allocation of the send buffer failed, this request must be cleaned up again. But indicator for such a failure is "ret == false". But the actual implementation is checking for "ret == true". The check must be inverted to not loose the information about the TT request directly after it was attempted to be sent out. This should avoid potential request storms.
Title batman-adv: tt: avoid request storms during pending request
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:41:48.586Z

Reserved: 2026-08-09T03:40:39.913Z

Link: CVE-2026-72231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:50.000

Modified: 2026-08-17T06:18:24.377

Link: CVE-2026-72231

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72231 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T20:30:17Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime