batman-adv: dat: acquire ARP hw source only after skb realloc

Summary

CVECVE-2026-80600
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-28 08:16:43 UTC
Updated2026-08-29 07:16:45 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after skb realloc The pskb_may_pull() called by batadv_get_vid() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

Risk And Classification

Primary CVSS: v3.1 9.8 CRITICAL from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.001760000 probability, percentile 0.072340000 (date 2026-08-28)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a a82fc217cb7a447313c76ebf9f09b100771b0ddf git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a 86aa79b43e5b561fd3648891165bd7313b541315 git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a d755cd001fa2c248e186c1fc3df3d11d97dc843c git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a 3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146 git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a 01678c53a7717a748aee388b6839e7b9761d641c git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a 3b4c70c40f2e135a50cd38fc61c7d23a296a9981 git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a 059a70e1d12d6d99310e0599d37b0323557569a8 git Not specified
CNA Linux Linux affected b61ec31c85756bbc898fb892555509afe709459a 48067b2ae4504500a7093d9e1e16b42e70330480 git Not specified
CNA Linux Linux affected 5.1 Not specified
CNA Linux Linux unaffected 5.1 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/d755cd001fa2c248e186c1fc3df3d11d97dc843c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a82fc217cb7a447313c76ebf9f09b100771b0ddf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/059a70e1d12d6d99310e0599d37b0323557569a8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/86aa79b43e5b561fd3648891165bd7313b541315 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3b4c70c40f2e135a50cd38fc61c7d23a296a9981 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/48067b2ae4504500a7093d9e1e16b42e70330480 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/01678c53a7717a748aee388b6839e7b9761d641c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report