CVE-2026-72234
Use-after-free in Linux batman-adv allows kernel compromise via crafted packets
Is CVE-2026-72234 being exploited?
Not confirmed. CVE-2026-72234 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.68% probability of exploitation in the next 30 days.
How severe is CVE-2026-72234?
CVE-2026-72234 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72234?
Yes. A fix has been recorded for CVE-2026-72234. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72234 affect?
CVE-2026-72234 affects Linux kernel (batman-adv module), Embedded routers/mesh devices using batman-adv, Network appliances running affected Linux kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72234?
Update to a patched Linux kernel ASAP and reboot affected hosts; block batman-adv traffic until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted network packets can trigger a use-after-free in batman-adv, causing kernel crash or remote kernel code execution and privilege escalation.
Immediate action required
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < aa9558af859934f24717d4bab97d61004f91a736
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < 9c2c05629e46c1fd43931506d41c56a885a98eb4
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < 7b162b36de750565404cd3b98315706622c6974f
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < ed90eb5c68420cdfe67ec1f773324198d2ef6f50
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < 979175834a699ccc3c4c0b0ba60ecae0f135a587
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < b8afcf799b2cc92c41beebd029e53ed18960184a
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < 9a7b7248798123efbd5fafe58461d57c7cc718af
- affected>= c018ad3de61a1dc4194879a53e5559e094aa7b1a and < 7141990add3f75436f2933cb310654cad3b1e3e9
- affected3.13
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.