{"api_version":"1","generated_at":"2026-08-29T12:12:05+00:00","cve":"CVE-2026-80600","urls":{"html":"https://cve.report/CVE-2026-80600","api":"https://cve.report/api/cve/CVE-2026-80600.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80600","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80600"},"summary":{"title":"batman-adv: dat: acquire ARP hw source only after skb realloc","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: acquire ARP hw source only after skb realloc\n\nThe pskb_may_pull() called by batadv_get_vid() could reallocate the buffer\nbehind the skb. Variables which were pointing to the old buffer need to be\nreassigned to avoid an use-after-free.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-28 08:16:43","updated_at":"2026-08-29 07:16:45"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/d755cd001fa2c248e186c1fc3df3d11d97dc843c","name":"https://git.kernel.org/stable/c/d755cd001fa2c248e186c1fc3df3d11d97dc843c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a82fc217cb7a447313c76ebf9f09b100771b0ddf","name":"https://git.kernel.org/stable/c/a82fc217cb7a447313c76ebf9f09b100771b0ddf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146","name":"https://git.kernel.org/stable/c/3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/059a70e1d12d6d99310e0599d37b0323557569a8","name":"https://git.kernel.org/stable/c/059a70e1d12d6d99310e0599d37b0323557569a8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/86aa79b43e5b561fd3648891165bd7313b541315","name":"https://git.kernel.org/stable/c/86aa79b43e5b561fd3648891165bd7313b541315","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3b4c70c40f2e135a50cd38fc61c7d23a296a9981","name":"https://git.kernel.org/stable/c/3b4c70c40f2e135a50cd38fc61c7d23a296a9981","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/48067b2ae4504500a7093d9e1e16b42e70330480","name":"https://git.kernel.org/stable/c/48067b2ae4504500a7093d9e1e16b42e70330480","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/01678c53a7717a748aee388b6839e7b9761d641c","name":"https://git.kernel.org/stable/c/01678c53a7717a748aee388b6839e7b9761d641c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80600","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80600","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a a82fc217cb7a447313c76ebf9f09b100771b0ddf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a 86aa79b43e5b561fd3648891165bd7313b541315 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a d755cd001fa2c248e186c1fc3df3d11d97dc843c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a 3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a 01678c53a7717a748aee388b6839e7b9761d641c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a 3b4c70c40f2e135a50cd38fc61c7d23a296a9981 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a 059a70e1d12d6d99310e0599d37b0323557569a8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b61ec31c85756bbc898fb892555509afe709459a 48067b2ae4504500a7093d9e1e16b42e70330480 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80600","cve":"CVE-2026-80600","epss":"0.001760000","percentile":"0.072340000","score_date":"2026-08-28","updated_at":"2026-08-29 00:12:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/batman-adv/distributed-arp-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"a82fc217cb7a447313c76ebf9f09b100771b0ddf","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"86aa79b43e5b561fd3648891165bd7313b541315","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"d755cd001fa2c248e186c1fc3df3d11d97dc843c","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"01678c53a7717a748aee388b6839e7b9761d641c","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"3b4c70c40f2e135a50cd38fc61c7d23a296a9981","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"059a70e1d12d6d99310e0599d37b0323557569a8","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"},{"lessThan":"48067b2ae4504500a7093d9e1e16b42e70330480","status":"affected","version":"b61ec31c85756bbc898fb892555509afe709459a","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/batman-adv/distributed-arp-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.1"},{"lessThan":"5.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"5.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: acquire ARP hw source only after skb realloc\n\nThe pskb_may_pull() called by batadv_get_vid() could reallocate the buffer\nbehind the skb. Variables which were pointing to the old buffer need to be\nreassigned to avoid an use-after-free."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - Triggered when batadv_batman_skb_recv() processes remote batman-adv unicast/broadcast ETH_P_BATMAN frames on an active mesh hard interface; crafted VLAN-tagged embedded DHCPACK payloads reach batadv_dat_snoop_incoming_dhcp_ack() over the mesh network without local victim access.\nAC:L - The attacker fully controls skb layout (batman header, 802.1Q tag, valid DHCPACK fields) to pass batadv_dat_check_dhcp_ack() and force batadv_dat_get_vid()->pskb_may_pull() skb reallocation before stale hw_src use; repeatable with no victim-timed race.\nPR:N - No privileges on the victim host are required; any unauthenticated mesh peer (or L2 source able to inject ETH_P_BATMAN frames onto an active batman-adv hard interface with DAT enabled) can drive batadv_recv_unicast_packet()/batadv_recv_bcast_packet() without local login or CAP_NET_ADMIN.\nUI:N - Exploitation is triggered solely by the attacker transmitting malicious batman-adv mesh packets; no victim user action (mounting, DHCP client activity, or runtime configuration changes) is needed beyond the victim already running an active mesh node.\nS:U - The use-after-free corrupts kernel heap memory within the batman-adv DAT subsystem on the mesh node and does not cross VM, container, or IOMMU boundaries to impact a separate security authority.\nC:H - Stale hw_src dereferences freed skb buffer memory; batadv_dat_entry_add() reads six bytes via ether_addr_copy(dat_entry->mac_addr, hw_src), constituting a kernel heap use-after-free that can disclose sensitive or attacker-influenced memory contents.\nI:H - UAF-derived bytes are written into kmalloc'd batadv_dat_entry objects in the distributed ARP table hash, providing heap corruption suitable for developing arbitrary kernel memory write or control-flow hijacking primitives.\nA:H - Use-after-free on the batman-adv RX path can cause kernel oops, panic, or hang when processing freed skb data during DAT updates, and associated heap corruption inherently threatens system availability even before full exploit development."}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:21:12.299Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/a82fc217cb7a447313c76ebf9f09b100771b0ddf"},{"url":"https://git.kernel.org/stable/c/86aa79b43e5b561fd3648891165bd7313b541315"},{"url":"https://git.kernel.org/stable/c/d755cd001fa2c248e186c1fc3df3d11d97dc843c"},{"url":"https://git.kernel.org/stable/c/3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146"},{"url":"https://git.kernel.org/stable/c/01678c53a7717a748aee388b6839e7b9761d641c"},{"url":"https://git.kernel.org/stable/c/3b4c70c40f2e135a50cd38fc61c7d23a296a9981"},{"url":"https://git.kernel.org/stable/c/059a70e1d12d6d99310e0599d37b0323557569a8"},{"url":"https://git.kernel.org/stable/c/48067b2ae4504500a7093d9e1e16b42e70330480"}],"title":"batman-adv: dat: acquire ARP hw source only after skb realloc","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80600","datePublished":"2026-08-28T06:48:27.351Z","dateReserved":"2026-08-26T14:34:25.771Z","dateUpdated":"2026-08-29T06:21:12.299Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-28 08:16:43","lastModifiedDate":"2026-08-29 07:16:45","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80600","Ordinal":"1","Title":"batman-adv: dat: acquire ARP hw source only after skb realloc","CVE":"CVE-2026-80600","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80600","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: acquire ARP hw source only after skb realloc\n\nThe pskb_may_pull() called by batadv_get_vid() could reallocate the buffer\nbehind the skb. Variables which were pointing to the old buffer need to be\nreassigned to avoid an use-after-free.","Type":"Description","Title":"batman-adv: dat: acquire ARP hw source only after skb realloc"}]}}}