CVE-2026-31657
In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow the pointer. The netlink claim dump path dereferences claim->backbone_gw->orig and takes claim->backbone_gw->crc_lock without pinning the underlying backbone gateway. batadv_bla_check_claim() still has the same naked pointer access pattern. Reuse batadv_bla_claim_get_backbone_gw() in both readers so they operate on a stable gateway reference until the read-side work is complete. This keeps the dump and claim-check paths aligned with the lifetime rules introduced for the other BLA claim readers.
- Affected products
- Linuxmint, Linux Kernel
- Linux Linux Kernel
- < 6.1.169, 6.6.135, 6.12.82, 6.18.23, 6.19.13, 3.5, 7.0
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2026-04-24
No indexed exploits for CVE-2026-31657 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-31657 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.