CVE-2026-72228

UnknownEPSS 0.21%

Last modified

CVE-2026-72228 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if leak on failed linearization If the skb has a frag_list, it must be linearized before it can be split using skb_split(). But when this step failed, it must not only free the skb but also take care of the reference to the already found primary_if.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if leak on failed linearization If the skb has a frag_list, it must be linearized before it can be split using skb_split(). But when this step failed, it must not only free the skb but also take care of the reference to the already found primary_if.

Metrics

EPSS Probability
0.21%

11.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= a6a73781b460c4fe2cf2c40400ac91dfddb353fa, < e59b1960f71521ce4eb4397c4e82f5285601ab57; >= 8f37aad74f46dd5d8b95fac17804b75f77931fa9, < c1b28432fd6345e0d2308f39c507ed5750c265d2; >= a063f2fba3fa633a599253b62561051ac185fa99, < 4f3bf293f7662500142234ae6f23725953690bc9; >= a063f2fba3fa633a599253b62561051ac185fa99, < d2148aeee93197ccf821114489775132f28eebf5; >= a063f2fba3fa633a599253b62561051ac185fa99, < db3c700826e8126fbdaa83468a9c4ee4ee65319f; >= a063f2fba3fa633a599253b62561051ac185fa99, < a90f4fff9025371bce5371daa610af957de8dd6a; >= a063f2fba3fa633a599253b62561051ac185fa99, < 777a88256d6f70672116e53400659cc417e1feaa; >= a063f2fba3fa633a599253b62561051ac185fa99, < 353d2c1d5492e53ae34f490a84494124dc3d3531; 5ed837a7e05bcba72bdcd86b12547ea5b796cc01; 5853618b022b8ed287a278540303e1b283d6f247; 3915341a935f3397f65a01580dc3bfc4cdf53d14; bea410635595f8efbec90c948da04c3613ef87ea; >= 5.10.117, < 5.10.261; >= 5.15.41, < 5.15.212; >= 4.14.280, < 4.15; >= 4.19.244, < 4.20; >= 5.4.195, < 5.5; >= 5.17.9, < 5.18
LinuxLinux5.18

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72228?
In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if leak on failed linearization If the skb has a frag_list, it must be linearized before it can be split using skb_split(). But when this step failed, it must not only free the skb but also take care of the reference to the already found primary_if.
How severe is CVE-2026-72228?
Severity scoring for CVE-2026-72228 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72228?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72228?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST