CVE-2026-80601 PUBLISHED

batman-adv: gw: acquire ethernet header only after skb realloc

Assigner: Linux
Reserved: 26.08.2026 Published: 28.08.2026 Updated: 28.08.2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: gw: acquire ethernet header only after skb realloc

The pskb_may_pull() called by batadv_get_vid() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to 2760b38222c8828b075802342fe3b91eb823d542 (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to 6c37f1166549c999ccd164b0cb6462d1ae68f8f6 (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to b79884a5567bf788fb76c30832467cf6a56f3c0d (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to afac8096bde4948e3caa7e4dd733867cfbd3018e (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to e3f4325e35dd6e76b80665f3510738ce34819753 (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to e6b43acd34b219b807e65096ce207b087942779d (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to 916dac5f2944f63f07f7b501acbea6737dbbed0e (excl.)
  • affected from 6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9 to 77880a3be88d378d60cc1e8f8ec70430e2ed0518 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.14 is affected
  • unaffected from 0 to 3.14 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References