-

CVE-2026-89950

batman-adv: mcast: linearize skbuff for packet generation

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: mcast: linearize skbuff for packet generation

batadv_mcast_forw_packet() and batadv_mcast_forw_scrape() is not only
called (indirectly) by the unsharing+linearizing batadv_recv_mcast_packet()
handler. When it is called (indirectly) by batadv_mcast_forw_mcsend() then
it will be unshared but not linearized. The SKB_LINEAR_ASSERT() can
therefore cause a fatal BUG().

The linearization should happen during the expansion of the head because
the scrape function can be hit already during the initial
batadv_mcast_forw_mode() selection code:

* batadv_interface_tx
* batadv_mcast_forw_mode
* batadv_mcast_forw_mode_by_count()
* batadv_mcast_forw_push()
  -> calls batadv_mcast_forw_expand_head() before everything else
* batadv_mcast_forw_push_tvlvs()
* batadv_mcast_forw_push_dests()
* batadv_mcast_forw_push_adjust_padding()
* batadv_mcast_forw_scrape()
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 90039133221e33964ccb4a536dad7eb0a372fff7
Version < a9603e0a7cb5e0cddc6b23af153cf7daafc5c55e
Status affected
Version 90039133221e33964ccb4a536dad7eb0a372fff7
Version < c32e5e25c41201c8c3b796a4ab2c45103187091e
Status affected
Version 90039133221e33964ccb4a536dad7eb0a372fff7
Version < 2879177539e3ece483a8e5406970373698e9a6c5
Status affected
Version 90039133221e33964ccb4a536dad7eb0a372fff7
Version < 6a30a59e2660afd03c975f1b8eae6a2301161197
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.8
Status affected
Version 0
Version < 6.8
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a9603e0a7cb5e0cddc6b23af153cf7daafc5c55e
https://git.kernel.org/stable/c/c32e5e25c41201c8c3b796a4ab2c45103187091e
https://git.kernel.org/stable/c/2879177539e3ece483a8e5406970373698e9a6c5
https://git.kernel.org/stable/c/6a30a59e2660afd03c975f1b8eae6a2301161197