CVE-2026-80599: batman-adv: dat: ensure accessible eth_hdr proto field

Published Aug 28, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: ensure accessible ethhdr proto field

When batadvgetvid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. But in contrast to other call sites, batadvdatgetvid() and its caller didn't make sure this is true. This could have caused an out-of-bounds access.

Affected Software

1 affected component
Linux Linux kernel

Event History

Aug 28, 2026
CVE Published
via MITRE·06:48 AM
Data Sourced
via MITRE·06:48 AM
Description

Frequently Asked Questions

1

What condition is required to trigger the out-of-bounds access?

The vulnerable path is reached when batadv_dat_get_vid() calls batadv_get_vid() without ensuring that the Ethernet header's protocol field is accessible. A packet or buffer with insufficient accessible data at that point could cause the out-of-bounds access.

2

Which systems are exposed?

The issue affects Linux kernel installations using the batman-adv DAT code path. The provided information does not identify affected kernel versions or state whether the configuration is enabled by default.

3

How can I determine whether a fix is available for my kernel?

Check whether your kernel source or vendor kernel includes one of the referenced stable commits: da3677b5ed362742d30ceab31bfafcdc74dc2642, 6d3ea37074bb747f745d28138f87745ba9bd97c5, or 7913935d41f166c367bbf7cc76a79e50044388e8.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203