Answer in brief
CVE-2026-63835 records a Unknown severity vulnerability in batman-adv: v: prevent OGM aggregation on disabled hardif. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-63835 records a Unknown severity vulnerability in batman-adv: v: prevent OGM aggregation on disabled hardif. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <d462ced79dd430200cf888984e8005da77fc810b || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <f79deaaf822ab0ee2424cf28781f9ab91576bea3 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <d3569327fc7395b2b0461a0a0cb77a0bb74786c0 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <97644fdaaf6446ffbe182c5eb804fceb5b1a51b7 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <f04dde74399431fb07abbdd9cd5d0ed624771d04 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <3d4548c96d6f21ac1a9b06c5f82f3ef439c87023 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <86ab6b6fb5b82163bf6c45780bb72150021d7349 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <d11c00b95b2a3b3934007fc003dccc6fdcc061ad | d462ced79dd430200cf888984e8005da77fc810b, f79deaaf822ab0ee2424cf28781f9ab91576bea3, d3569327fc7395b2b0461a0a0cb77a0bb74786c0, 97644fdaaf6446ffbe182c5eb804fceb5b1a51b7, f04dde74399431fb07abbdd9cd5d0ed624771d04, 3d4548c96d6f21ac1a9b06c5f82f3ef439c87023, 86ab6b6fb5b82163bf6c45780bb72150021d7349, d11c00b95b2a3b3934007fc003dccc6fdcc061ad |
| Linux/Linuxgeneric | 5.4 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: prevent OGM aggregation on disabled hardif When an interface gets disabled, the worker is correctly disabled by batadv_hardif_disable_interface() -> ... -> batadv_v_ogm_iface_disable(). In this process, the skb aggr_list is also freed. But batadv_v_ogm_send_meshif() can still queue new skbs (via batadv_v_ogm_queue_on_if()) to the aggr_list. This will only stop after all cores can no longer find the RCU protected list of hard interfaces. These queued skbs will never be freed or consumed by batadv_v_ogm_aggr_work. The batadv_v_ogm_iface_disable() function must block batadv_v_ogm_queue_on_if() to avoid leak of skbs.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <d462ced79dd430200cf888984e8005da77fc810b || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <f79deaaf822ab0ee2424cf28781f9ab91576bea3 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <d3569327fc7395b2b0461a0a0cb77a0bb74786c0 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <97644fdaaf6446ffbe182c5eb804fceb5b1a51b7 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <f04dde74399431fb07abbdd9cd5d0ed624771d04 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <3d4548c96d6f21ac1a9b06c5f82f3ef439c87023 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <86ab6b6fb5b82163bf6c45780bb72150021d7349 || >=f89255a02f1d75d8e1b9d1c31435fcb64840cb2a <d11c00b95b2a3b3934007fc003dccc6fdcc061ad | d462ced79dd430200cf888984e8005da77fc810b, f79deaaf822ab0ee2424cf28781f9ab91576bea3, d3569327fc7395b2b0461a0a0cb77a0bb74786c0, 97644fdaaf6446ffbe182c5eb804fceb5b1a51b7, f04dde74399431fb07abbdd9cd5d0ed624771d04, 3d4548c96d6f21ac1a9b06c5f82f3ef439c87023, 86ab6b6fb5b82163bf6c45780bb72150021d7349, d11c00b95b2a3b3934007fc003dccc6fdcc061ad |
| Linux/Linuxgeneric | 5.4 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: prevent OGM aggregation on disabled hardif When an interface gets disabled, the worker is correctly disabled by batadv_hardif_disable_interface() -> ... -> batadv_v_ogm_iface_disable(). In this process, the skb aggr_list is also freed. But batadv_v_ogm_send_meshif() can still queue new skbs (via batadv_v_ogm_queue_on_if()) to the aggr_list. This will only stop after all cores can no longer find the RCU protected list of hard interfaces. These queued skbs will never be freed or consumed by batadv_v_ogm_aggr_work. The batadv_v_ogm_iface_disable() function must block batadv_v_ogm_queue_on_if() to avoid leak of skbs.
Quoted source text, attributed separately from HOL analysis.