CyberRota
← Ana sayfaya dön

CVE-2026-52934

HIGH · CVSS 8.8 EPSS %0.25

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-24T08:16:23.620 · Çekilme zamanı: 2026-06-30T18:31:12.021736+00:00

CyberRota Yorumu

Bellek tüketimine neden olabilir.

CVE
CVE-2026-52934
Severity
HIGH
CVSS
8.8
EPSS
%0.25
Linux

Orijinal NVD Açıklaması

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_append() builds a TVLV packet section from the tvlv.container_list. The total size of this section is computed by batadv_tvlv_container_list_size(), which sums the sizes of all registered containers. The return type and accumulator in batadv_tvlv_container_list_size() were u16. If the accumulated size exceeds U16_MAX, the value wraps around, causing the subsequent allocation in batadv_tvlv_container_ogm_append() to be undersized. The memcpy-style copy that follows would then write beyond the end of the allocated buffer, corrupting kernel memory. Fix this by widening the return type of batadv_tvlv_container_list_size() to size_t. In batadv_tvlv_container_ogm_append(), check the computed length against U16_MAX before proceeding, and bail out as if the allocation had failed when the limit is exceeded.