Answer in brief
CVE-2026-72232 records a Unknown severity vulnerability in batman-adv: ensure minimal ethernet header on TX. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72232 records a Unknown severity vulnerability in batman-adv: ensure minimal ethernet header on TX. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <58799078afebd5115e052bf69ad6697f9759dd6f || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <38cd10b0aeec755d89f78722a2b83f4088ff0cb0 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <811fea37620f2097955d95ce81cfdba03fd30f1b || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <e6640923afee619d9fa82b07394dc9498e202304 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <6b4f521e01257387906f8b969ad3450d8208d4e2 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <9e16b6751a8206de0b865d99bb02771e6751d12d || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <dbeb4145d9778f922f459935da9a027750765a69 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <49df66b7993c80b80c7eb9a84ba5b3410c8296a0 | 58799078afebd5115e052bf69ad6697f9759dd6f, 38cd10b0aeec755d89f78722a2b83f4088ff0cb0, 811fea37620f2097955d95ce81cfdba03fd30f1b, e6640923afee619d9fa82b07394dc9498e202304, 6b4f521e01257387906f8b969ad3450d8208d4e2, 9e16b6751a8206de0b865d99bb02771e6751d12d, dbeb4145d9778f922f459935da9a027750765a69, 49df66b7993c80b80c7eb9a84ba5b3410c8296a0 |
| Linux/Linuxgeneric | 2.6.38 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a local user with eBPF TC hook access to attach a tc filter which truncates the packet and redirects to an batadv interface. But the code assumes that at least ETH_HLEN bytes are available and thus might read outside of the available buffer. The batadv_interface_tx() must therefore always check itself if enough data is available for the ethernet header and don't rely on min_header_len.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <58799078afebd5115e052bf69ad6697f9759dd6f || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <38cd10b0aeec755d89f78722a2b83f4088ff0cb0 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <811fea37620f2097955d95ce81cfdba03fd30f1b || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <e6640923afee619d9fa82b07394dc9498e202304 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <6b4f521e01257387906f8b969ad3450d8208d4e2 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <9e16b6751a8206de0b865d99bb02771e6751d12d || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <dbeb4145d9778f922f459935da9a027750765a69 || >=c6c8fea29769d998d94fcec9b9f14d4b52b349d3 <49df66b7993c80b80c7eb9a84ba5b3410c8296a0 | 58799078afebd5115e052bf69ad6697f9759dd6f, 38cd10b0aeec755d89f78722a2b83f4088ff0cb0, 811fea37620f2097955d95ce81cfdba03fd30f1b, e6640923afee619d9fa82b07394dc9498e202304, 6b4f521e01257387906f8b969ad3450d8208d4e2, 9e16b6751a8206de0b865d99bb02771e6751d12d, dbeb4145d9778f922f459935da9a027750765a69, 49df66b7993c80b80c7eb9a84ba5b3410c8296a0 |
| Linux/Linuxgeneric | 2.6.38 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a local user with eBPF TC hook access to attach a tc filter which truncates the packet and redirects to an batadv interface. But the code assumes that at least ETH_HLEN bytes are available and thus might read outside of the available buffer. The batadv_interface_tx() must therefore always check itself if enough data is available for the ethernet header and don't rely on min_header_len.
Quoted source text, attributed separately from HOL analysis.