Executive brief
The batman-adv Distributed ARP Table (DAT) module in the Linux kernel failed to validate packet buffer boundaries before accessing ethernet header fields, potentially allowing out-of-bounds memory reads. This could be exploited by crafting malicious network packets to cause kernel crashes or information disclosure on systems using batman-adv mesh networking.
Technical details
The vulnerability is a missing bounds check in the batman-adv DAT (Distributed ARP Table) module. The function batadv_get_vid() accesses the proto field of an ethernet header without verifying that sufficient buffer data is accessible. While the caller is responsible for ensuring data accessibility, multiple call sites in batadv_dat_snoop_outgoing_arp_request(), batadv_dat_snoop_incoming_arp_request(), batadv_dat_snoop_outgoing_arp_reply(), batadv_dat_snoop_incoming_arp_reply(), and batadv_dat_drop_broadcast_packet() failed to perform this check. An attacker can send specially crafted ARP packets over a mesh network to trigger an out-of-bounds access. The fix adds pskb_may_pull() checks to ensure at least ETH_HLEN + header_size bytes are accessible before calling batadv_dat_get_vid().
Affected products
- Linux Linux kernel Multiple versions (fixed in various stable branches)
Timeline
- 2026-08-28: disclosed
- 2026-06-28: patched: Initial upstream fix committed by Sven Eckelmann