CVE-2026-72235
Use-after-free in Linux batman-adv RX path enabling kernel memory corruption.
Is CVE-2026-72235 being exploited?
Not confirmed. CVE-2026-72235 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.34% probability of exploitation in the next 30 days.
How severe is CVE-2026-72235?
CVE-2026-72235 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72235?
Yes. A fix has been recorded for CVE-2026-72235. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72235 affect?
CVE-2026-72235 affects Linux kernel with batman-adv enabled, Embedded/mesh routers, OpenWrt-based devices, IoT mesh devices. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72235?
Update to patched kernel or unload/disable batman-adv; block mesh traffic until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can send crafted packets to trigger kernel use-after-free, causing crash/DoS or possible kernel privilege escalation/RCE.
Immediate action required
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < 6e189f14d1ea28db212b9d70a02131a7ce518012
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < a1820344b180cb55af748f102bc536b5c93164db
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < 6abf73589bed3f27ee240c08108feb72bed0b9c6
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < f19259395b44af67f3c274e34237c295b526b859
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < 2cefa5141cab8ec1e4b24cf585958b13f2e3049d
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < 85a71a81854e0e191ad0e533eabb4eff54866feb
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < b031fc97e1993d29d6c3a0e86a99140528cf31e8
- affected>= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 and < 035e1fed892d3d06002a73ff73668f618a514644
- affected2.6.38
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.