CVE-2014-9428: Linux Kernel

High severity, CVSS 7.8. EPSS: 5.4% chance of exploitation in the next 30 days.

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a denial of service (mesh-node system crash) via fragmented packets.

Affected products

  • Linux Linux Kernel: from 3.13, before 3.14.30 (fixed in 3.14.30); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.4 (fixed in 3.18.4)

Published 2015-01-02. Last modified 2026-06-17.