Out-of-bounds read in Linux kernel - CVE-2026-80599
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in batadv_dat_get_vid() when processing packet data without ensuring the ethernet header is accessible. A local user can provide a specially crafted skb to trigger an out-of-bounds access and cause a denial of service.
The issue affects distributed arp table handling paths.
Affected software
How to mitigate CVE-2026-80599
External References
- https://git.kernel.org/stable/c/26560c4a03dc4d607331600c187f59ab2df5f341
- https://git.kernel.org/stable/c/3c62694c31f043568c3f4784b8d247cc3bea6b4c
- https://git.kernel.org/stable/c/4407ff3af469356f9641c4a6e7072309bae86bea
- https://git.kernel.org/stable/c/5836a050d02e9598fa0f71e88dde28b63dfa35e3
- https://git.kernel.org/stable/c/6d3ea37074bb747f745d28138f87745ba9bd97c5
- https://git.kernel.org/stable/c/7913935d41f166c367bbf7cc76a79e50044388e8
- https://git.kernel.org/stable/c/8f76277d02176cd739945bba3379448e2e22e799
- https://git.kernel.org/stable/c/da3677b5ed362742d30ceab31bfafcdc74dc2642