In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: prevent TVLV OOB check overflow
A TT unicast TVLV contains the number of VLANs stored in it. This number is
an u16 and gets multiplied by the size of the struct
batadv_tvlv_tt_vlan_data (8 bytes). The size can therefore overflow the u16
used to store the tt_vlan_len. All additional safety checks to prevent
out-of-bounds access of the TVLV buffer are invalid due to this overflow.
Using size_t prevents this overflow and ensures that the safety checks
compare against the actual buffer requirements.
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
AV:N - Crafted BATADV_UNICAST_TVLV frames from remote mesh peers reach batadv_tt_tvlv_unicast_handler_v1() via batadv_batman_skb_recv() → batadv_recv_unicast_tvlv() → batadv_tvlv_containers_process() without local syscall or ioctl access on the victim.
AC:L - An attacker reliably bypasses TVLV bounds checks by setting num_vlan so flex_array_size() overflows the u16 tt_vlan_len (e.g. 8192 VLANs wraps length to 4); all packet fields are attacker-controlled with no races or victim-state dependencies.
PR:N - batman-adv TVLV receive processing performs no authentication or capability check on senders; any unauthenticated mesh peer injecting ETH_P_BATMAN unicast TVLV frames to an active mesh node triggers the vulnerable path without Linux credentials on the victim.
UI:N - Exploitation is triggered solely by the attacker transmitting malicious mesh packets; no victim mount, click, or runtime configuration change is required beyond batman-adv already being active on a mesh interface.
S:U - Out-of-bounds reads and translation-table corruption occur within the victim kernel networking subsystem on the mesh node; the flaw does not cross VM, container, IOMMU, or other separate security-authority boundaries.
C:H - Overflowed tt_vlan_len invalidates the length check, so batadv_handle_tt_response() offsets tt_change by struct_size() far beyond the skb and _batadv_tt_update_changes() performs out-of-bounds reads of kernel memory for each computed entry.
I:H - Out-of-bounds tt_change data drives batadv_tt_global_add()/batadv_tt_global_del() and batadv_tt_fill_gtable(), writing attacker-influenced or leaked bytes into kmalloc-backed translation-table objects suitable for heap corruption and control-flow hijacking.
A:H - Dereferencing tt_change pointers tens of kilobytes past the packet buffer can cause kernel oops or panic, and corrupt translation-table updates can destabilize or disable mesh routing on the victim node.
| Attack Vector |
Network |
Scope |
Unchanged |
| Attack Complexity |
Low |
Confidentiality Impact |
High |
| Privileges Required |
None |
Integrity Impact |
High |
| User Interaction |
None |
Availability Impact |
High |
AV:N - Crafted BATADV_UNICAST_TVLV frames from remote mesh peers reach batadv_tt_tvlv_unicast_handler_v1() via batadv_batman_skb_recv() → batadv_recv_unicast_tvlv() → batadv_tvlv_containers_process() without local syscall or ioctl access on the victim.
AC:L - An attacker reliably bypasses TVLV bounds checks by setting num_vlan so flex_array_size() overflows the u16 tt_vlan_len (e.g. 8192 VLANs wraps length to 4); all packet fields are attacker-controlled with no races or victim-state dependencies.
PR:N - batman-adv TVLV receive processing performs no authentication or capability check on senders; any unauthenticated mesh peer injecting ETH_P_BATMAN unicast TVLV frames to an active mesh node triggers the vulnerable path without Linux credentials on the victim.
UI:N - Exploitation is triggered solely by the attacker transmitting malicious mesh packets; no victim mount, click, or runtime configuration change is required beyond batman-adv already being active on a mesh interface.
S:U - Out-of-bounds reads and translation-table corruption occur within the victim kernel networking subsystem on the mesh node; the flaw does not cross VM, container, IOMMU, or other separate security-authority boundaries.
C:H - Overflowed tt_vlan_len invalidates the length check, so batadv_handle_tt_response() offsets tt_change by struct_size() far beyond the skb and _batadv_tt_update_changes() performs out-of-bounds reads of kernel memory for each computed entry.
I:H - Out-of-bounds tt_change data drives batadv_tt_global_add()/batadv_tt_global_del() and batadv_tt_fill_gtable(), writing attacker-influenced or leaked bytes into kmalloc-backed translation-table objects suitable for heap corruption and control-flow hijacking.
A:H - Dereferencing tt_change pointers tens of kilobytes past the packet buffer can cause kernel oops or panic, and corrupt translation-table updates can destabilize or disable mesh routing on the victim node.
CVSS 3.1