CVE-2026-72231
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: avoid request storms during pending request
batadv_send_tt_request() allocates a tt_req_node when none exists for the destination originator node. This should prevent that a multiple TT requests are send at the same time to an originator.
But if allocation of the send buffer failed, this request must be cleaned up again. But indicator for such a failure is "ret == false". But the actual implementation is checking for "ret == true".
The check must be inverted to not loose the information about the TT request directly after it was attempted to be sent out. This should avoid potential request storms.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.72%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access45 % - Impacto principal
T1499.004Application or System Exploitationimpact75 %
Vulnerabilidad de DoS en kernel Linux (batman-adv) con vector de red sin privilegios (AV:N/PR:N). La falla en la limpieza de solicitudes genera tormentas (request storms) que agotan recursos, causando indisponibilidad del servicio.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/067e413eec2e63c2996909ef55214b3a0eda0be7
- https://git.kernel.org/stable/c/21c44a6895f41df811d1c91d10eea194dda2b345
- https://git.kernel.org/stable/c/27c7d40008231ae4140d35501b60087a9de2d2c3
- https://git.kernel.org/stable/c/5e46c76d9a5062212c4c5f642a5549fd9c057f8a
- https://git.kernel.org/stable/c/6055695ea40c64a47e00742c12c99b1a33b4daed
- https://git.kernel.org/stable/c/6a65ac8a81e903bb4b555c1d13532f5cb0167a4a
- https://git.kernel.org/stable/c/716f434eb35869e130424331584a91fbb729b9bd
- https://git.kernel.org/stable/c/aba1cf21954e64c36afb966b754adad2b0b8aa48
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72231",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "6055695ea40c64a47e00742c12c99b1a33b4daed",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "21c44a6895f41df811d1c91d10eea194dda2b345",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "5e46c76d9a5062212c4c5f642a5549fd9c057f8a",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "067e413eec2e63c2996909ef55214b3a0eda0be7",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "716f434eb35869e130424331584a91fbb729b9bd",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "6a65ac8a81e903bb4b555c1d13532f5cb0167a4a",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "aba1cf21954e64c36afb966b754adad2b0b8aa48",
"versionType": "git"
},
{
"status": "affected",
"version": "335fbe0f5d2501b7dd815806aef6fd9bad784eb1",
"lessThan": "27c7d40008231ae4140d35501b60087a9de2d2c3",
"versionType": "git"
}
],
"programFiles": [
"net/batman-adv/translation-table.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/batman-adv/translation-table.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:50.000",
"references": [
{
"url": "https://git.kernel.org/stable/c/067e413eec2e63c2996909ef55214b3a0eda0be7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/21c44a6895f41df811d1c91d10eea194dda2b345",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/27c7d40008231ae4140d35501b60087a9de2d2c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e46c76d9a5062212c4c5f642a5549fd9c057f8a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6055695ea40c64a47e00742c12c99b1a33b4daed",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6a65ac8a81e903bb4b555c1d13532f5cb0167a4a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/716f434eb35869e130424331584a91fbb729b9bd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aba1cf21954e64c36afb966b754adad2b0b8aa48",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: avoid request storms during pending request\n\nbatadv_send_tt_request() allocates a tt_req_node when none exists for the\ndestination originator node. This should prevent that a multiple TT\nrequests are send at the same time to an originator.\n\nBut if allocation of the send buffer failed, this request must be cleaned\nup again. But indicator for such a failure is \"ret == false\". But the\nactual implementation is checking for \"ret == true\".\n\nThe check must be inverted to not loose the information about the TT\nrequest directly after it was attempted to be sent out. This should avoid\npotential request storms."
}
],
"lastModified": "2026-08-17T06:18:24.377",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}