CVE-2026-72228: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if leak on failed linearization If the skb has a frag_list, it must be linearized before it can be split using skb_split(). But when this step failed, it must not only free the skb but also take care of the reference to the already found primary_if.

Affected products

  • Linux Linux: from 5.10.117, before 5.10.261 (fixed in 5.10.261); from 5.15.41, before 5.15.212 (fixed in 5.15.212); from 4.14.280, before 4.15 (fixed in 4.15); from 4.19.244, before 4.20 (fixed in 4.20); from 5.4.195, before 5.5 (fixed in 5.5); from 5.17.9, before 5.18 (fixed in 5.18); …

Published 2026-08-15. Last modified 2026-08-17.