PULSE
EN VIVO20señales / 24h
FEED
ransomplay reclama a First Tek · TW · Technologyransomplay reclama a Preferred Financial Group · US · Financial Servicesransomthegentlemen reclama a TopMark Funding · US · Financial Servicesransomthegentlemen reclama a Control Concepts Technology · US · Technologyransomchaos reclama a healthcarehighways.com · US · Healthcareransomgunra reclama a worldtube · KR · Technologyransomqilin reclama a WD Masonry & Concrete · US · Otherransomakira reclama a University SprinklerSystems · Manufacturingransomorova reclama a Tat Fung Textile Co., Ltd. · HK · Manufacturingransomorova reclama a Integrated Site Management · US · Professional Servicesransomorova reclama a Conceptual Designs, Inc. · US · Otherransomorova reclama a JK Capital Management Limited · HK · Financial Servicesransomorova reclama a Global Friction Products, Inc · US · Manufacturingransomaurora reclama a GILDE Handwerk Macrander GmbH & Co. KG · DE · Manufacturingransomplay reclama a First Tek · TW · Technologyransomplay reclama a Preferred Financial Group · US · Financial Servicesransomthegentlemen reclama a TopMark Funding · US · Financial Servicesransomthegentlemen reclama a Control Concepts Technology · US · Technologyransomchaos reclama a healthcarehighways.com · US · Healthcareransomgunra reclama a worldtube · KR · Technologyransomqilin reclama a WD Masonry & Concrete · US · Otherransomakira reclama a University SprinklerSystems · Manufacturingransomorova reclama a Tat Fung Textile Co., Ltd. · HK · Manufacturingransomorova reclama a Integrated Site Management · US · Professional Servicesransomorova reclama a Conceptual Designs, Inc. · US · Otherransomorova reclama a JK Capital Management Limited · HK · Financial Servicesransomorova reclama a Global Friction Products, Inc · US · Manufacturingransomaurora reclama a GILDE Handwerk Macrander GmbH & Co. KG · DE · Manufacturing
← Todos los CVEs
CVE Watch27 jul 2026

CVE-2026-63836

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd The cwnd is al

CVSS

Sin CVSS

EPSS

0.2%

p7

KEV

Exploit Today

2

0-100

Publicado: 19 jul 2026 · Última mod.: 27 jul 2026

EPSS · 30d
0.2%EPSS · 30 días0.2%
2026-07-202026-08-03
Descripción técnica

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd The cwnd is always MSS <= cwnd <= 0x20000000. But the calculation in batadv_tp_update_cwnd() assumes unsigned 32 bit arithmetics. ((mss * 8) ** 2) / (cwnd * 8) In case cwnd is actually 0x20000000, it will be shifted by 3 bit to the left end up at 0x100000000 or U32_MAX + 1. It will therefore wrap around and be 0 - resulting in: ((mss * 8) ** 2) / 0 This is of course invalid and cannot be calculated. The calculation should must be simplified to avoid this overflow: (mss ** 2) * 8 / cwnd It will keep the precision enhancement from the scaling (by 8) but avoid the overflow in the divisor. In theory, there could still be an overflow in the dividend. It is at the moment fixed to BATADV_TP_PLEN in batadv_tp_recv_ack() - so it is not an imminent problem. But allowing it to use the whole u32 bit range, would mean that it can still use up to 67 bits. To keep this calculation safe for 32 bit arithmetic, mss must never use more than floor((32 - 3) / 2) bits - or in other words: must never be larger than 16383.

Referencias oficiales
CVEs relacionados

Sin CVEs relacionados por CWE o producto.