CVE-2026-52931
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tp_meter: avoid use of uninit sender vars
batadvtprecvack() and batadvtpstop() are only valid for tpvars in the
BATADVTPSENDER role. When called with a BATADVTPRECEIVER role, it
proceeds to read sender-only members that were never initialized, leading
to undefined behavior.
This can be triggered when a node that is currently acting as a receiver in
an ongoing tp_meter session receives a malicious ACK packet.
Guard against this by checking tp_vars->role immediately after the
lookup and bailing out if it is not BATADVTPSENDER, before any of
those members are accessed.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/0e388af04b3958b178a1b979527f93eb46ea1fee, https://git.kernel.org/stable/c/1a21c055f66e78973712a4a1be2a554f1ee2e4f4, https://git.kernel.org/stable/c/53f931e0146ae5bdab4cba302646827d06b3794b, https://git.kernel.org/stable/c/6c65cf23d4c6170fcf5714c32aa64689718cb142, https://git.kernel.org/stable/c/85397e48afe6be83ffca5ad3f4792296bfc81d3d, https://git.kernel.org/stable/c/9884c9c02d3c90e9215db3c5128f59045d20ae91, https://git.kernel.org/stable/c/dc2ae5fbd2dadc26735092f140b246841d969a11, https://git.kernel.org/stable/c/ecdaa3e4d91040206afe21bc8a0d1198a0971ff3, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52931.json, https://nvd.nist.gov/vuln/detail/CVE-2026-52931, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git