Answer in brief
CVE-2026-80839 records a Unknown severity vulnerability in batman-adv: reject unrepresentable multicast TVLV offsets. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=07afe1ba288c04280622fa002ed385f1ac0b6fe6 <da1f5aa7ec93f2cc17f5cd30efc54f62af433cf2 || >=07afe1ba288c04280622fa002ed385f1ac0b6fe6 <916ec741e65af072b98e475feaad98c063da1b7c || >=07afe1ba288c04280622fa002ed385f1ac0b6fe6 <1b466746fe109127fd983100a228cdd1f1f6ece2 || >=07afe1ba288c04280622fa002ed385f1ac0b6fe6 <2b46baa591d0a7c16b62f150917187e70d053be6 || >=07afe1ba288c04280622fa002ed385f1ac0b6fe6 <f12c2de4f542e3220e17e0606f492110064f04cb | da1f5aa7ec93f2cc17f5cd30efc54f62af433cf2, 916ec741e65af072b98e475feaad98c063da1b7c, 1b466746fe109127fd983100a228cdd1f1f6ece2, 2b46baa591d0a7c16b62f150917187e70d053be6, f12c2de4f542e3220e17e0606f492110064f04cb |
| Linux/Linuxgeneric | 6.8 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject unrepresentable multicast TVLV offsets The network and transport header fields in struct sk_buff are 16-bit offsets from skb->head, and U16_MAX is reserved as the unset transport header value. batadv_tvlv_call_handler() sets both fields from a received multicast TVLV without checking whether the TVLV end is representable. If the end offset exceeds the field's range, skb_set_transport_header() truncates it so that the transport header precedes the network header. The negative difference is then returned by skb_network_header_len() as a large u32. batadv_mcast_forw_packet() consequently accepts an oversized multicast tracker and accesses memory beyond the skb data. Add skb_set_transport_header_careful(), an offset-aware counterpart to skb_reset_transport_header_careful(), which validates the final head-relative offset before assigning it. Use the new helper in batadv_tvlv_call_handler() and reject unrepresentable TVLVs before setting the network header.
Quoted source text, attributed separately from HOL analysis.