batman-adv: ensure minimal ethernet header on TX

Summary

CVECVE-2026-72232
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:21:50 UTC
Updated2026-08-17 06:18:24 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a local user with eBPF TC hook access to attach a tc filter which truncates the packet and redirects to an batadv interface. But the code assumes that at least ETH_HLEN bytes are available and thus might read outside of the available buffer. The batadv_interface_tx() must therefore always check itself if enough data is available for the ethernet header and don't rely on min_header_len.

Risk And Classification

Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.001560000 probability, percentile 0.052340000 (date 2026-08-17)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 58799078afebd5115e052bf69ad6697f9759dd6f git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 38cd10b0aeec755d89f78722a2b83f4088ff0cb0 git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 811fea37620f2097955d95ce81cfdba03fd30f1b git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 e6640923afee619d9fa82b07394dc9498e202304 git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 6b4f521e01257387906f8b969ad3450d8208d4e2 git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 9e16b6751a8206de0b865d99bb02771e6751d12d git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 dbeb4145d9778f922f459935da9a027750765a69 git Not specified
CNA Linux Linux affected c6c8fea29769d998d94fcec9b9f14d4b52b349d3 49df66b7993c80b80c7eb9a84ba5b3410c8296a0 git Not specified
CNA Linux Linux affected 2.6.38 Not specified
CNA Linux Linux unaffected 2.6.38 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/58799078afebd5115e052bf69ad6697f9759dd6f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e6640923afee619d9fa82b07394dc9498e202304 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/811fea37620f2097955d95ce81cfdba03fd30f1b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6b4f521e01257387906f8b969ad3450d8208d4e2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9e16b6751a8206de0b865d99bb02771e6751d12d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/49df66b7993c80b80c7eb9a84ba5b3410c8296a0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dbeb4145d9778f922f459935da9a027750765a69 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/38cd10b0aeec755d89f78722a2b83f4088ff0cb0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report