Resource exhaustion in Linux kernel - CVE-2026-63834
Published: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the batman-adv tp_meter unacked_list handling when processing crafted messages with small lengths and seqno gaps. A remote attacker can send specially crafted messages to cause a denial of service.
The issue can lead to an out-of-memory condition or excessive CPU usage from management overhead while searching the enlarged list.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-63834
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/1111a3381bca2d1f084a07686bc783af5ab23df7
- https://git.kernel.org/stable/c/1c616b0be4bd8399d485e25e91859373b95d6013
- https://git.kernel.org/stable/c/1fb8762600a393d1caccd63be5d07e1756982d68
- https://git.kernel.org/stable/c/2233787658db859f0a9b83cb397cf783bb8be865
- https://git.kernel.org/stable/c/31a88792bfba142be3c9521538c1db805677381f
- https://git.kernel.org/stable/c/c6231d628d06d841bc1617b2f7034f5f39876b16
- https://git.kernel.org/stable/c/e7c775110e1858e5a7471a23a9c9658c0af9df89
- https://git.kernel.org/stable/c/f8c499fd275e59203b77fca76ae6ef2d096c2133