AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72229

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's batman-adv module, specifically during the registration of mesh interfaces, where improper handling can lead to resource leaks if the registration is vetoed. This could potentially impact system stability and resource management in environments utilizing mesh networking. Organizations using Linux systems with batman-adv should prioritize addressing this issue to ensure optimal performance and security of their network infrastructure.

CVE
CVE-2026-72229
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: batman-adv: clean untagged VLAN on netdev registration failure When an mesh interface is registered, it creates an untagged struct batadv_meshif_vlan on top of it via the NETDEV_REGISTER notifier. But in this process, another receiver of this notification can veto the registration. The netdev registration will be aborted because of this veto. The register_netdevice() call will try to clean up the net_device using unregister_netdevice_queue() - which only uses the .priv_destructor to free private resources. In this situation, .dellink will not be called. The cleanup of the untagged batadv_meshif_vlan must thefore be done in the destructor to avoid a leak of this object.