{"id":"CVE-2026-63834","summary":"batman-adv: tp_meter: restrict number of unacked list entries","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: restrict number of unacked list entries\n\nWhen the unacked_list is unbound, an attacker could send messages with\nsmall lengths and appropriated seqno + gaps to force the receiver to\nallocate more and more unacked_list entries. And the end either causing an\nout-of-memory situation or increase the management overhead for the (large)\nlist that significant portions of CPU cycles are wasted in searching\nthrough the list.\n\nWhen limiting the list to a specific number, it is important to still\ncorrectly add a new entry to the list. But if the list became larger than\nthe limit, the last entry of the list (with the highest seqno) must be\ndropped to still allow the earlier seqnos to finish and therefore to\ncontinue the process. Otherwise, the process might get stuck with too high\nseqnos which are not handled by batadv_tp_ack_unordered().","modified":"2026-07-21T03:47:33.753131138Z","published":"2026-07-19T12:02:26.045Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63834.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1111a3381bca2d1f084a07686bc783af5ab23df7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1c616b0be4bd8399d485e25e91859373b95d6013"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1fb8762600a393d1caccd63be5d07e1756982d68"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2233787658db859f0a9b83cb397cf783bb8be865"},{"type":"WEB","url":"https://git.kernel.org/stable/c/31a88792bfba142be3c9521538c1db805677381f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c6231d628d06d841bc1617b2f7034f5f39876b16"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e7c775110e1858e5a7471a23a9c9658c0af9df89"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f8c499fd275e59203b77fca76ae6ef2d096c2133"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63834.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63834"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e"},{"fixed":"31a88792bfba142be3c9521538c1db805677381f"},{"fixed":"1111a3381bca2d1f084a07686bc783af5ab23df7"},{"fixed":"1c616b0be4bd8399d485e25e91859373b95d6013"},{"fixed":"f8c499fd275e59203b77fca76ae6ef2d096c2133"},{"fixed":"c6231d628d06d841bc1617b2f7034f5f39876b16"},{"fixed":"2233787658db859f0a9b83cb397cf783bb8be865"},{"fixed":"1fb8762600a393d1caccd63be5d07e1756982d68"},{"fixed":"e7c775110e1858e5a7471a23a9c9658c0af9df89"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63834.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.8.0"},{"fixed":"5.10.260"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.211"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.177"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.144"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.95"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.38"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63834.json"}}],"schema_version":"1.7.5"}