LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31657

CVE-2026-31657 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 27, 2026

Linux kernel batman-adv - Use After Free

Published: April 24, 2026Updated: April 27, 2026Remote Exploitable

Overview

Linux kernel batman-adv contains a use-after-free vulnerability caused by improper reference handling of backbone gateways in batadv_bla_add_claim and related functions, letting attackers cause memory corruption or denial of service, exploit requires kernel-level access.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 5.7%(Probability of exploitation in next 30 days)

Impact

Attackers with kernel access can cause memory corruption or denial of service by exploiting improper reference handling.

Mitigation

Update to the latest Linux kernel version containing the fix.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 28, 2026

šŸ”“ CVE-2026-31657 - Critical (9.8) In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-31657/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-31657
Severity
Critical
CVSS Score
9.8
Type
use_after_free
Status
unconfirmed
EPSS
5.7%
Social Posts
1

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

5.7%Probability of exploitation in the next 30 days