{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80599","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.771Z","datePublished":"2026-08-28T06:48:26.709Z","dateUpdated":"2026-08-29T06:21:11.082Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:21:11.082Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: ensure accessible eth_hdr proto field\n\nWhen batadv_get_vid() accesses the proto field of the ethernet header, it\nis not checking if the data itself is accessible. The caller is responsible\nfor it. But in contrast to other call sites, batadv_dat_get_vid() and its\ncaller didn't make sure this is true. This could have caused an\nout-of-bounds access."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - Exploitation requires injecting crafted ETH_P_BATMAN frames on the victim's batman-adv hard interface via batadv_batman_skb_recv(); an attacker must be on the same L2 mesh segment (WiFi community mesh, industrial mesh, or shared Ethernet backbone), not arbitrary Internet routing.\nAC:L - The attacker fully controls remote packet length and contents; sending a batman-adv unicast or broadcast frame with only the batman header (10 or 14 bytes) and no embedded Ethernet payload bypasses hdr_size-only pskb_may_pull checks and deterministically forces the h_proto read past skb->tail without races or rare configuration.\nPR:N - No Linux account or capability on the victim is required; any unauthenticated mesh peer that can transmit ETH_P_BATMAN frames to an active batman-adv node with Distributed ARP Table enabled reaches batadv_dat_snoop_incoming_*() through the normal RX handler without local login or CAP_NET_ADMIN on the target.\nUI:N - The vulnerable path runs automatically in softirq when the mesh interface receives qualifying traffic; no victim mount, click, or administrative action is needed beyond batman-adv already running with DAT enabled (the default at mesh interface creation).\nS:U - Impact is an out-of-bounds kernel read during batman-adv packet processing on the receiving mesh node; it does not cross a VM, container, or IOMMU security boundary to affect a different authority's resources.\nC:H - batadv_get_vid() reads ethhdr->h_proto (2 bytes at offset 12 within the embedded Ethernet header) without ensuring hdr_size+ETH_HLEN bytes are accessible, causing an out-of-bounds read of adjacent skb tailroom or slab memory beyond the packet buffer per kernel OOB-read guidance.\nI:N - This is an out-of-bounds read only with no memory write or corruption; subsequent batadv_arp_get_type() performs its own pskb_may_pull() before further parsing, and the DAT snoop path returns without modifying kernel structures beyond the illicit read.\nA:H - Reading past skb->tail in NET_RX_SOFTIRQ can provoke a kernel oops or panic when the access crosses an unmapped page boundary, denying mesh and host connectivity; any out-of-bounds kernel access on the packet receive path is rated high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/batman-adv/distributed-arp-table.c","net/batman-adv/main.c"],"versions":[{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"da3677b5ed362742d30ceab31bfafcdc74dc2642","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"6d3ea37074bb747f745d28138f87745ba9bd97c5","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"7913935d41f166c367bbf7cc76a79e50044388e8","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"3c62694c31f043568c3f4784b8d247cc3bea6b4c","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"5836a050d02e9598fa0f71e88dde28b63dfa35e3","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"8f76277d02176cd739945bba3379448e2e22e799","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"4407ff3af469356f9641c4a6e7072309bae86bea","status":"affected","versionType":"git"},{"version":"be1db4f6615b5e6156c807ea8985171c215c2d57","lessThan":"26560c4a03dc4d607331600c187f59ab2df5f341","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/batman-adv/distributed-arp-table.c","net/batman-adv/main.c"],"versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/da3677b5ed362742d30ceab31bfafcdc74dc2642"},{"url":"https://git.kernel.org/stable/c/6d3ea37074bb747f745d28138f87745ba9bd97c5"},{"url":"https://git.kernel.org/stable/c/7913935d41f166c367bbf7cc76a79e50044388e8"},{"url":"https://git.kernel.org/stable/c/3c62694c31f043568c3f4784b8d247cc3bea6b4c"},{"url":"https://git.kernel.org/stable/c/5836a050d02e9598fa0f71e88dde28b63dfa35e3"},{"url":"https://git.kernel.org/stable/c/8f76277d02176cd739945bba3379448e2e22e799"},{"url":"https://git.kernel.org/stable/c/4407ff3af469356f9641c4a6e7072309bae86bea"},{"url":"https://git.kernel.org/stable/c/26560c4a03dc4d607331600c187f59ab2df5f341"}],"title":"batman-adv: dat: ensure accessible eth_hdr proto field","x_generator":{"engine":"bippy-1.2.0"}}}}