CVE-2026-72235

Source
https://cve.org/CVERecord?id=CVE-2026-72235
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72235.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-72235
Downstream
Published
2026-08-15T05:54:25Z
Modified
2026-08-18T04:17:29Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
batman-adv: retrieve ethhdr after potential skb realloc on RX
Details

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: retrieve ethhdr after potential skb realloc on RX

pskb_may_pull() in batadv_interface_rx() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

This was done correctly for the VLAN header but missed for the ethernet header which is later used for the TT and AP isolation handling.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72235.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c6c8fea29769d998d94fcec9b9f14d4b52b349d3
Fixed
6e189f14d1ea28db212b9d70a02131a7ce518012
Fixed
a1820344b180cb55af748f102bc536b5c93164db
Fixed
6abf73589bed3f27ee240c08108feb72bed0b9c6
Fixed
f19259395b44af67f3c274e34237c295b526b859
Fixed
2cefa5141cab8ec1e4b24cf585958b13f2e3049d
Fixed
85a71a81854e0e191ad0e533eabb4eff54866feb
Fixed
b031fc97e1993d29d6c3a0e86a99140528cf31e8
Fixed
035e1fed892d3d06002a73ff73668f618a514644

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72235.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.38
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72235.json"