Linux Kernel Vulnerability in batman-adv Multicast Handling from Vendor Linux
CVE-2026-80839
What is CVE-2026-80839?
A vulnerability exists in the Linux kernel's batman-adv module, which improperly processes multicast TVLV offsets. When a multicast TVLV is received, the batadv_tvlv_call_handler function fails to validate the representation of offset values. This oversight can lead to memory access violations, as oversized multicast tracker values may be accepted, allowing access beyond allocated skb data. The introduction of skb_set_transport_header_careful() addresses this issue by validating offsets before modifying headers, mitigating potential exploitation risks.
Affected Version(s)
Linux 07afe1ba288c04280622fa002ed385f1ac0b6fe6
Linux 07afe1ba288c04280622fa002ed385f1ac0b6fe6 < 916ec741e65af072b98e475feaad98c063da1b7c
Linux 07afe1ba288c04280622fa002ed385f1ac0b6fe6 < 1b466746fe109127fd983100a228cdd1f1f6ece2