CVE-2026-72228
Last modified
CVE-2026-72228 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if leak on failed linearization If the skb has a frag_list, it must be linearized before it can be split using skb_split(). But when this step failed, it must not only free the skb but also take care of the reference to the already found primary_if.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if leak on failed linearization If the skb has a frag_list, it must be linearized before it can be split using skb_split(). But when this step failed, it must not only free the skb but also take care of the reference to the already found primary_if.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= a6a73781b460c4fe2cf2c40400ac91dfddb353fa, < e59b1960f71521ce4eb4397c4e82f5285601ab57; >= 8f37aad74f46dd5d8b95fac17804b75f77931fa9, < c1b28432fd6345e0d2308f39c507ed5750c265d2; >= a063f2fba3fa633a599253b62561051ac185fa99, < 4f3bf293f7662500142234ae6f23725953690bc9; >= a063f2fba3fa633a599253b62561051ac185fa99, < d2148aeee93197ccf821114489775132f28eebf5; >= a063f2fba3fa633a599253b62561051ac185fa99, < db3c700826e8126fbdaa83468a9c4ee4ee65319f; >= a063f2fba3fa633a599253b62561051ac185fa99, < a90f4fff9025371bce5371daa610af957de8dd6a; >= a063f2fba3fa633a599253b62561051ac185fa99, < 777a88256d6f70672116e53400659cc417e1feaa; >= a063f2fba3fa633a599253b62561051ac185fa99, < 353d2c1d5492e53ae34f490a84494124dc3d3531; 5ed837a7e05bcba72bdcd86b12547ea5b796cc01; 5853618b022b8ed287a278540303e1b283d6f247; 3915341a935f3397f65a01580dc3bfc4cdf53d14; bea410635595f8efbec90c948da04c3613ef87ea; >= 5.10.117, < 5.10.261; >= 5.15.41, < 5.15.212; >= 4.14.280, < 4.15; >= 4.19.244, < 4.20; >= 5.4.195, < 5.5; >= 5.17.9, < 5.18 |
| Linux | Linux | 5.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72228?
How severe is CVE-2026-72228?
How do I fix CVE-2026-72228?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72222In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72223In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72224In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72225In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72226In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72227In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-72229In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7223A vulnerability was identified in BigSweetPotatoStudio Hyper…7.3
- CVE-2026-72230In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72231In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-72232In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72233In the Linux kernel, the following vulnerability has been re…8.8
Are you affected by CVE-2026-72228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
