« Volver al listado

CVE-2026-31657

Estado: ModificadaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: hold claim backbone gateways by reference

batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow the pointer.

The netlink claim dump path dereferences claim->backbone_gw->orig and takes claim->backbone_gw->crc_lock without pinning the underlying backbone gateway. batadv_bla_check_claim() still has the same naked pointer access pattern.

Reuse batadv_bla_claim_get_backbone_gw() in both readers so they operate on a stable gateway reference until the read-side work is complete. This keeps the dump and claim-check paths aligned with the lifetime rules introduced for the other BLA claim readers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de referencia nula (CWE-476) en kernel Linux accesible remotamente sin autenticación (AV:N/PR:N/UI:N), explotable a través de la pila de red Batman-adv. El derreferenciamiento de punteros inestables en el manejo de gateway permite corrupción de memoria y potencialmente ejecución de có

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-31657",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "5202f071b367ffbc8e279fc7a00db14f5e587f52",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "69d1ce9c72eca91203ffdb8d08bacd511100aec6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "f4858832ddef2f39f21e30b7226bbcd3c4b2bc96",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "2f55b58b5a0bbed192d60c444a45a49cdf1b545f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "7962b522222628596ca9ecc8722efc95367aadbd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "4dee4c0688443aaf5bbec74aa203c851d1d53c35",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "1f2dc36c297d27733f1b380ea644cf15a361bd7b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23721387c409087fd3b97e274f34d3ddc0970b74",
              "lessThan": "82d8701b2c930d0e96b0dbc9115a218d791cb0d2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/batman-adv/bridge_loop_avoidance.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.169",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.135",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.82",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.23",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.13",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/batman-adv/bridge_loop_avoidance.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-04-24T15:16:45.227",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1f2dc36c297d27733f1b380ea644cf15a361bd7b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2f55b58b5a0bbed192d60c444a45a49cdf1b545f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4dee4c0688443aaf5bbec74aa203c851d1d53c35",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5202f071b367ffbc8e279fc7a00db14f5e587f52",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/69d1ce9c72eca91203ffdb8d08bacd511100aec6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7962b522222628596ca9ecc8722efc95367aadbd",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/82d8701b2c930d0e96b0dbc9115a218d791cb0d2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f4858832ddef2f39f21e30b7226bbcd3c4b2bc96",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: hold claim backbone gateways by reference\n\nbatadv_bla_add_claim() can replace claim->backbone_gw and drop the old\ngateway's last reference while readers still follow the pointer.\n\nThe netlink claim dump path dereferences claim->backbone_gw->orig and\ntakes claim->backbone_gw->crc_lock without pinning the underlying\nbackbone gateway. batadv_bla_check_claim() still has the same naked\npointer access pattern.\n\nReuse batadv_bla_claim_get_backbone_gw() in both readers so they operate\non a stable gateway reference until the read-side work is complete.\nThis keeps the dump and claim-check paths aligned with the lifetime\nrules introduced for the other BLA claim readers."
    }
  ],
  "lastModified": "2026-06-17T10:34:10.713",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17B3C5B3-0F63-4D6D-A3AA-C6184C350124",
              "versionEndExcluding": "6.1.169",
              "versionStartIncluding": "3.5.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15C1A1B2-14EE-494C-AF3E-D5A7BA640B39",
              "versionEndExcluding": "6.6.135",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02904CAE-71D2-45B3-9EC3-F6A9D18B6307",
              "versionEndExcluding": "6.12.82",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9E09FDD-9EE3-4A56-92E2-2B30AFD0072F",
              "versionEndExcluding": "6.18.23",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1490EF9B-9080-481C-8D22-1306AAE664E4",
              "versionEndExcluding": "6.19.13",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.5:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71555F5B-DEB2-417A-8E33-90276DD2EFB8"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58A9FEFF-C040-420D-8F0A-BFDAAA1DF258"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D2315C0-D46F-4F85-9754-F9E5E11374A6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "512EE3A8-A590-4501-9A94-5D4B268D6138"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}