CVE-2026-80600 (GCVE-0-2026-80600)
Vulnerability from cvelistv5
Published
2026-08-28 06:48
Modified
2026-08-29 06:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: acquire ARP hw source only after skb realloc
The pskb_may_pull() called by batadv_get_vid() could reallocate the buffer
behind the skb. Variables which were pointing to the old buffer need to be
reassigned to avoid an use-after-free.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a Version: b61ec31c85756bbc898fb892555509afe709459a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/batman-adv/distributed-arp-table.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a82fc217cb7a447313c76ebf9f09b100771b0ddf",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "86aa79b43e5b561fd3648891165bd7313b541315",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "d755cd001fa2c248e186c1fc3df3d11d97dc843c",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "01678c53a7717a748aee388b6839e7b9761d641c",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "3b4c70c40f2e135a50cd38fc61c7d23a296a9981",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "059a70e1d12d6d99310e0599d37b0323557569a8",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
},
{
"lessThan": "48067b2ae4504500a7093d9e1e16b42e70330480",
"status": "affected",
"version": "b61ec31c85756bbc898fb892555509afe709459a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/batman-adv/distributed-arp-table.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: acquire ARP hw source only after skb realloc\n\nThe pskb_may_pull() called by batadv_get_vid() could reallocate the buffer\nbehind the skb. Variables which were pointing to the old buffer need to be\nreassigned to avoid an use-after-free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Triggered when batadv_batman_skb_recv() processes remote batman-adv unicast/broadcast ETH_P_BATMAN frames on an active mesh hard interface; crafted VLAN-tagged embedded DHCPACK payloads reach batadv_dat_snoop_incoming_dhcp_ack() over the mesh network without local victim access.\nAC:L - The attacker fully controls skb layout (batman header, 802.1Q tag, valid DHCPACK fields) to pass batadv_dat_check_dhcp_ack() and force batadv_dat_get_vid()-\u003epskb_may_pull() skb reallocation before stale hw_src use; repeatable with no victim-timed race.\nPR:N - No privileges on the victim host are required; any unauthenticated mesh peer (or L2 source able to inject ETH_P_BATMAN frames onto an active batman-adv hard interface with DAT enabled) can drive batadv_recv_unicast_packet()/batadv_recv_bcast_packet() without local login or CAP_NET_ADMIN.\nUI:N - Exploitation is triggered solely by the attacker transmitting malicious batman-adv mesh packets; no victim user action (mounting, DHCP client activity, or runtime configuration changes) is needed beyond the victim already running an active mesh node.\nS:U - The use-after-free corrupts kernel heap memory within the batman-adv DAT subsystem on the mesh node and does not cross VM, container, or IOMMU boundaries to impact a separate security authority.\nC:H - Stale hw_src dereferences freed skb buffer memory; batadv_dat_entry_add() reads six bytes via ether_addr_copy(dat_entry-\u003emac_addr, hw_src), constituting a kernel heap use-after-free that can disclose sensitive or attacker-influenced memory contents.\nI:H - UAF-derived bytes are written into kmalloc\u0027d batadv_dat_entry objects in the distributed ARP table hash, providing heap corruption suitable for developing arbitrary kernel memory write or control-flow hijacking primitives.\nA:H - Use-after-free on the batman-adv RX path can cause kernel oops, panic, or hang when processing freed skb data during DAT updates, and associated heap corruption inherently threatens system availability even before full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:21:12.299Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a82fc217cb7a447313c76ebf9f09b100771b0ddf"
},
{
"url": "https://git.kernel.org/stable/c/86aa79b43e5b561fd3648891165bd7313b541315"
},
{
"url": "https://git.kernel.org/stable/c/d755cd001fa2c248e186c1fc3df3d11d97dc843c"
},
{
"url": "https://git.kernel.org/stable/c/3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146"
},
{
"url": "https://git.kernel.org/stable/c/01678c53a7717a748aee388b6839e7b9761d641c"
},
{
"url": "https://git.kernel.org/stable/c/3b4c70c40f2e135a50cd38fc61c7d23a296a9981"
},
{
"url": "https://git.kernel.org/stable/c/059a70e1d12d6d99310e0599d37b0323557569a8"
},
{
"url": "https://git.kernel.org/stable/c/48067b2ae4504500a7093d9e1e16b42e70330480"
}
],
"title": "batman-adv: dat: acquire ARP hw source only after skb realloc",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80600",
"datePublished": "2026-08-28T06:48:27.351Z",
"dateReserved": "2026-08-26T14:34:25.771Z",
"dateUpdated": "2026-08-29T06:21:12.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…