CVE-2026-72226
Linux batman-adv TT TVLV integer overflow leads to kernel OOB memory corruption
Is CVE-2026-72226 being exploited?
Not confirmed. CVE-2026-72226 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.70% probability of exploitation in the next 30 days.
How severe is CVE-2026-72226?
CVE-2026-72226 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72226?
Yes. A fix has been recorded for CVE-2026-72226. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72226 affect?
CVE-2026-72226 affects Linux kernel (batman-adv module), Embedded/firmware routers running batman-adv (e.g., OpenWrt), Devices participating in B.A.T.M.A.N. mesh networks. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72226?
Apply vendor/kernel updates; disable batman-adv on exposed devices if unused.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted batman-adv TT TVLV packets can trigger an integer overflow and OOB kernel memory corruption, causing crashes or potential remote kernel compromise.
Immediate action required
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 0de12a4c4847f571d82a9cd96bc633eded41d7c6
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < d6ff4764ff784ede25f5c83a6f5883a74c93a5ea
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 1898273c5dc8148267ef9f97cd2517a2822350e7
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 604bd5042fbcd1ab9f7cd98fd847ec017aeede8a
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 7319c0794f91be2734aac695794e7203606b49f8
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 3256c05d5a9db34346eaf20f52dddde984852d77
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 6222b443686525cb5a9b6a9cecf23b2e2ab23e2a
- affected>= 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b and < 7a581d9aaba8c82bd6177fa36b2588eea77f6e2b
- affected3.13
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.