PT-2026-35143 · Linux · Linux Kernel

Published

2026-04-25

·

Updated

2026-05-06

·

CVE-2026-31683

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the batman-adv module where OGM aggregation can lead to a buffer overflow. When the OGM aggregation state is toggled during runtime, a forwarded packet might be allocated with only packet len bytes. If a subsequent packet is selected for aggregation and appended, it can trigger skb put overflow conditions if the target skb tailroom is insufficient to accommodate the new packet.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-31683
ECHO-DFC6-ED7D-9BDC

Affected Products

Linux Kernel