CVE-2026-72226 PUBLISHED

batman-adv: tt: prevent TVLV OOB check overflow

Assigner: Linux
Reserved: 09.08.2026 Published: 15.08.2026 Updated: 17.08.2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: tt: prevent TVLV OOB check overflow

A TT unicast TVLV contains the number of VLANs stored in it. This number is an u16 and gets multiplied by the size of the struct batadv_tvlv_tt_vlan_data (8 bytes). The size can therefore overflow the u16 used to store the tt_vlan_len. All additional safety checks to prevent out-of-bounds access of the TVLV buffer are invalid due to this overflow.

Using size_t prevents this overflow and ensures that the safety checks compare against the actual buffer requirements.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

AV:N - Crafted BATADV_UNICAST_TVLV frames from remote mesh peers reach batadv_tt_tvlv_unicast_handler_v1() via batadv_batman_skb_recv() → batadv_recv_unicast_tvlv() → batadv_tvlv_containers_process() without local syscall or ioctl access on the victim. AC:L - An attacker reliably bypasses TVLV bounds checks by setting num_vlan so flex_array_size() overflows the u16 tt_vlan_len (e.g. 8192 VLANs wraps length to 4); all packet fields are attacker-controlled with no races or victim-state dependencies. PR:N - batman-adv TVLV receive processing performs no authentication or capability check on senders; any unauthenticated mesh peer injecting ETH_P_BATMAN unicast TVLV frames to an active mesh node triggers the vulnerable path without Linux credentials on the victim. UI:N - Exploitation is triggered solely by the attacker transmitting malicious mesh packets; no victim mount, click, or runtime configuration change is required beyond batman-adv already being active on a mesh interface. S:U - Out-of-bounds reads and translation-table corruption occur within the victim kernel networking subsystem on the mesh node; the flaw does not cross VM, container, IOMMU, or other separate security-authority boundaries. C:H - Overflowed tt_vlan_len invalidates the length check, so batadv_handle_tt_response() offsets tt_change by struct_size() far beyond the skb and _batadv_tt_update_changes() performs out-of-bounds reads of kernel memory for each computed entry. I:H - Out-of-bounds tt_change data drives batadv_tt_global_add()/batadv_tt_global_del() and batadv_tt_fill_gtable(), writing attacker-influenced or leaked bytes into kmalloc-backed translation-table objects suitable for heap corruption and control-flow hijacking. A:H - Dereferencing tt_change pointers tens of kilobytes past the packet buffer can cause kernel oops or panic, and corrupt translation-table updates can destabilize or disable mesh routing on the victim node.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 0de12a4c4847f571d82a9cd96bc633eded41d7c6 (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to d6ff4764ff784ede25f5c83a6f5883a74c93a5ea (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 1898273c5dc8148267ef9f97cd2517a2822350e7 (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 604bd5042fbcd1ab9f7cd98fd847ec017aeede8a (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 7319c0794f91be2734aac695794e7203606b49f8 (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 3256c05d5a9db34346eaf20f52dddde984852d77 (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 6222b443686525cb5a9b6a9cecf23b2e2ab23e2a (excl.)
  • affected from 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b to 7a581d9aaba8c82bd6177fa36b2588eea77f6e2b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.13 is affected
  • unaffected from 0 to 3.13 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References