CVE-2026-72226: Linux
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB check overflow A TT unicast TVLV contains the number of VLANs stored in it. This number is an u16 and gets multiplied by the size of the struct batadv_tvlv_tt_vlan_data (8 bytes). The size can therefore overflow the u16 used to store the tt_vlan_len. All additional safety checks to prevent out-of-bounds access of the TVLV buffer are invalid due to this overflow. Using size_t prevents this overflow and ensures that the safety checks compare against the actual buffer requirements.
Affected products
- Linux Linux: from 3.13, before 5.10.261 (fixed in 5.10.261); from 5.11, before 5.15.212 (fixed in 5.15.212); from 5.16, before 6.1.178 (fixed in 6.1.178); from 6.2, before 6.6.145 (fixed in 6.6.145); from 6.7, before 6.12.97 (fixed in 6.12.97); from 6.13, before 6.18.40 (fixed in 6.18.40); …
Published 2026-08-15. Last modified 2026-08-17.