CVE-2026-72233

Source
https://cve.org/CVERecord?id=CVE-2026-72233
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72233.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72233
Downstream
Published
2026-08-15T05:54:23Z
Modified
2026-08-18T03:56:39Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
batman-adv: bla: reacquire gw address after skb realloc
Details

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: bla: reacquire gw address after skb realloc

The pskb_may_pull() called by batadv_bla_is_backbone_gw() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72233.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9e794b6bf4a2c65d698d7433ddfabc54a5d53a88
Fixed
41819c5467b6eb8ab4567f0ac98702ce9b6abbb1
Fixed
a9ab19fbca86b32e9a9ae9e1a63e70a7eab3400f
Fixed
4a6673c55752a7aa41e28f51660eb981504ca088
Fixed
ab2bac47a02637df1128a151e81d3ec14767f4bb
Fixed
dc16bbf53cede1baf564bf0c8a861114b64e18b3
Fixed
e5e18886aadd3870e2d84e32a9678317fab1dd9e
Fixed
f4fb97ecf677cd9c3aa4f3bfc6fbf5b0e4bdbbbf
Fixed
cdf3b5af2bc4431e58629e8ad2086b1e9185c761

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72233.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72233.json"