CVE-2026-80839
CVE CVE-2026-80839EUVD EUVD-2026-71289Published 2026-09-04T15:54:49.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject unrepresentable multicast TVLV offsets The network and transport header fields in struct sk_buff are 16-bit offsets from skb->head, and U16_MAX is reserved as the unset transport header value. batadv_tvlv_call_handler() sets both fields from a received multicast TVLV without checking whether the TVLV end is representable. If the end offset exceeds the field's range, skb_set_transport_header() truncates it so that the transport header precedes the network header. The negative difference is then returned by skb_network_header_len() as a large u32. batadv_mcast_forw_packet() consequently accepts an oversized multicast tracker and accesses memory beyond the skb data. Add skb_set_transport_header_careful(), an offset-aware counterpart to skb_reset_transport_header_careful(), which validates the final head-relative offset before assigning it. Use the new helper in batadv_tvlv_call_handler() and reject unrepresentable TVLVs before setting the network header.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.49; 07afe1ba288c04280622fa002ed385f1ac0b6fe6 <1b466746fe109127fd983100a228cdd1f1f6ece2; 07afe1ba288c04280622fa002ed385f1ac0b6fe6 <2b46baa591d0a7c16b62f150917187e70d053be6; 07afe1ba288c04280622fa002ed385f1ac0b6fe6 <da1f5aa7ec93f2cc17f5cd30efc54f62af433cf2; 6.8; patch: 0; 07afe1ba288c04280622fa002ed385f1ac0b6fe6 <916ec741e65af072b98e475feaad98c063da1b7c; patch: 7.2.3; patch: 6.12.108; patch: 7.1.13; patch: 7.3-rc1; 07afe1ba288c04280622fa002ed385f1ac0b6fe6 <f12c2de4f542e3220e17e0606f492110064f04cb
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.