CVE-2026-72232
In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a local user with eBPF TC hook access to attach a tc filter which truncates the packet and redirects to an batadv interface. But the code assumes that at least ETH_HLEN bytes are available and thus might read outside of the available buffer. The batadv_interface_tx() must therefore always check itself if enough data is available for the ethernet header and don't rely on min_header_len.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.16% probability · 5th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/38cd10b0aeec755d89f78722a2b83f4088ff0cb0
- https://git.kernel.org/stable/c/49df66b7993c80b80c7eb9a84ba5b3410c8296a0
- https://git.kernel.org/stable/c/58799078afebd5115e052bf69ad6697f9759dd6f
- https://git.kernel.org/stable/c/6b4f521e01257387906f8b969ad3450d8208d4e2
- https://git.kernel.org/stable/c/811fea37620f2097955d95ce81cfdba03fd30f1b
- https://git.kernel.org/stable/c/9e16b6751a8206de0b865d99bb02771e6751d12d
- https://git.kernel.org/stable/c/dbeb4145d9778f922f459935da9a027750765a69
- https://git.kernel.org/stable/c/e6640923afee619d9fa82b07394dc9498e202304
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.