PT-2026-82899 · Linux · Linux

CVE-2026-80599

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: ensure accessible eth hdr proto field
When batadv get vid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. But in contrast to other call sites, batadv dat get vid() and its caller didn't make sure this is true. This could have caused an out-of-bounds access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80599

Affected Products

Linux