{"@context":"https://openvex.dev/ns/v0.2.0","@id":"https://database.harborguard.co/cve/CVE-2026-52931/vex.json","author":"HarborGuard Database","role":"Document Creator","timestamp":"2026-06-28T06:36:51.143Z","version":1,"tooling":"HarborGuard Database (https://database.harborguard.co)","statements":[{"vulnerability":{"name":"CVE-2026-52931","@id":"https://www.cve.org/CVERecord?id=CVE-2026-52931","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: avoid use of uninit sender vars\n\nbatadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the\nBATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it\nproceeds to read sender-only members that were never initialized, leading\nto undefined behavior.\n\nThis can be triggered when a node that is currently acting as a receiver in\nan ongoing tp_meter session receives a malicious ACK pac"},"products":[{"@id":"cpe:2.3:a:linux:linux:*:*:*:*:*:*:*:*","identifiers":{"cpe23":"cpe:2.3:a:linux:linux:*:*:*:*:*:*:*:*"}},{"@id":"cpe:2.3:a:linux:linux:4.8:*:*:*:*:*:*:*","identifiers":{"cpe23":"cpe:2.3:a:linux:linux:4.8:*:*:*:*:*:*:*"}}],"status":"affected","action_statement":"Update to a fixed version: 0, 0e388af04b3958b178a1b979527f93eb46ea1fee, 1a21c055f66e78973712a4a1be2a554f1ee2e4f4, 5.10.258, 5.15.209, 53f931e0146ae5bdab4cba302646827d06b3794b, 6.1.175, 6.6.142, 6.12.92, 6.18.34, 6c65cf23d4c6170fcf5714c32aa64689718cb142, 7.0.11, 7.1, 85397e48afe6be83ffca5ad3f4792296bfc81d3d, 9884c9c02d3c90e9215db3c5128f59045d20ae91, dc2ae5fbd2dadc26735092f140b246841d969a11, ecdaa3e4d91040206afe21bc8a0d1198a0971ff3.","timestamp":"2026-06-28T06:36:51.143Z"}]}