Junglewise Threat Intelligence

CVE-2026-80601: Linux kernel batman-adv use-after-free in gateway client

CVE-2026-80601 · Severity: high · CVSS 8.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

Batman-adv is a mesh networking component in the Linux kernel used for ad-hoc wireless networking. A use-after-free vulnerability in the gateway client code can allow local attackers to crash the system or potentially execute code with kernel privileges, compromising system stability and security.

Technical details

This vulnerability is a use-after-free flaw in the batman-adv gateway_client.c module. The root cause is that batadv_get_vid() calls pskb_may_pull(), which can reallocate the socket buffer (skb) behind the pointer. The ethhdr pointer, which was initialized before the pskb_may_pull() call, becomes stale and points to freed memory. The fix reorders the code to assign the ethhdr pointer only after the skb reallocation. The vulnerability is triggered when processing network packets in the gateway range check function batadv_gw_out_of_range(). Local network access is required to trigger this condition; no special privileges are needed beyond the ability to send packets through the mesh network interface.

Affected products

  • Linux Linux Kernel Multiple versions affected (patches applied across 2.6.x, 3.x, 4.x, 5.x, 6.x, and 7.x series)

Timeline

  • 2026-08-28: disclosed: CVE-2026-80601 published
  • 2026-06-28: patched: Upstream fix committed
  • 2026-07-24: patched: Backported to stable kernel branches

References

Related threats