PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52913 Linux Kernel CVE debrief

A vulnerability in the Linux kernel's batman-adv module has been addressed. The issue involves stopping OGMv2 on disabled interfaces to prevent NULL pointer dereferences. This vulnerability could impact Linux kernel users and administrators who need to ensure their systems are updated to prevent potential exploitation. The vulnerability class is related to improper handling of disabled interfaces in the batman-adv module.

Vendor
Linux Kernel
Product
batman-adv (Linux kernel module)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-07-08
Advisory published
2026-06-24
Advisory updated
2026-07-08

Who should care

Linux kernel users and administrators should be aware of this vulnerability and take steps to ensure their systems are updated. This includes reviewing system configurations, monitoring for potential issues with the batman-adv module, and verifying that all Linux kernel modules are up-to-date. Operators, platform administrators, and security teams may need to review and update their vulnerability management processes.

Technical summary

The Linux kernel's batman-adv module had a vulnerability where OGMv2 was not properly stopped on disabled interfaces, leading to a potential NULL pointer dereference. This has been resolved by adding checks to ensure that batadv_v_ogm_queue_on_if() uses the same mesh_iface for which batadv_v_ogm_send_meshif() was called. The technical impact includes potential system crashes or unexpected behavior if exploited. The fix involves updating the Linux kernel to the latest version.

Defensive priority

Medium

Recommended defensive actions

  • Update the Linux kernel to the latest version
  • Verify that all Linux kernel modules are up-to-date
  • Monitor system logs for potential issues with the batman-adv module
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-06-24T08:16:21.080Z and last modified on 2026-07-07T18:35:34.340Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects the Linux kernel's batman-adv module, specifically in how it handles OGMv2 on disabled interfaces. Evidence is limited, and defenders should verify system configurations and monitor for potential issues. The CVE details are based on the official CVE record and NVD entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52913 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52913

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52913 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52913

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/040fe8eb34624002071dd21de9824dfe668ce65d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1be1e99cbd5b74a69d3f92200ca87cf1bce852db

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/31dcb9711abd1dcd2080d9fac05c79dd9997d6bf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4ff461af943efb5e74d09942d5ffee7644d1e1fe

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/70c9f6ab0d8f785087fb74fb85464a9a5288bfdb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/aad70db50ea3d7dfe30e402b889ff075a293b287

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d7391a2b854a62235539c68e9cbf6fc7910a8e9a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.