Linux Kernel batman-adv NULL Pointer Deref via batadv_dat_forward_data
CVE-2026-52922 Published on June 24, 2026
batman-adv: dat: handle forward allocation error
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: handle forward allocation error
batadv_dat_forward_data() calls pskb_copy_for_clone() to duplicate an skb
for each DHT candidate, but does not check the return value before passing
it to batadv_send_skb_prepare_unicast_4addr(). That function dereferences
the skb unconditionally, so a failed allocation triggers a NULL pointer
dereference.
Skip forwarding to the current DHT candidate on allocation failure.
Products Associated with CVE-2026-52922
stack.watch emails you whenever new vulnerabilities are published in Linux Kernel or Canonical Ubuntu Linux. Just hit a watch button to start following.
Affected Versions
Linux:- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below 9bcebaedfb8479cb4affb23c7a0d000ca9a20e73 is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below 2edb8aeb3cdda9d00ec4997252dc5bcd6f54d8ef is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below ce0c381199402a2c58f4599f4f6ed100d872d0da is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below 866ac1d57040ed0b44ca732e3c66b3aa6b93011c is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below 4d420d9ee70a220a2cd95aa0dd2e15acad66a505 is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below 9cceea8eeba710def2a5707ee00f00c74a9a1cac is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below cf48e75fc4fe0d5cc7721c82d454221d01367b93 is affected.
- Version 785ea1144182c341b8b85b0f8180291839d176a8 and below 2d8826a2d3657cea66fb0370f9e521575a673871 is affected.
- Version 3.8 is affected.
- Before 3.8 is unaffected.
- Version 5.10.258, <= 5.10.* is unaffected.
- Version 5.15.209, <= 5.15.* is unaffected.
- Version 6.1.175, <= 6.1.* is unaffected.
- Version 6.6.142, <= 6.6.* is unaffected.
- Version 6.12.92, <= 6.12.* is unaffected.
- Version 6.18.34, <= 6.18.* is unaffected.
- Version 7.0.11, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.