CVE-2026-80599

Source
https://cve.org/CVERecord?id=CVE-2026-80599
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80599.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80599
Downstream
Published
2026-08-28T06:48:26.709Z
Modified
2026-08-31T03:30:47.986372207Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
batman-adv: dat: ensure accessible eth_hdr proto field
Details

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: ensure accessible eth_hdr proto field

When batadvgetvid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. But in contrast to other call sites, batadvdatget_vid() and its caller didn't make sure this is true. This could have caused an out-of-bounds access.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80599.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
be1db4f6615b5e6156c807ea8985171c215c2d57
Fixed
da3677b5ed362742d30ceab31bfafcdc74dc2642
Fixed
6d3ea37074bb747f745d28138f87745ba9bd97c5
Fixed
7913935d41f166c367bbf7cc76a79e50044388e8
Fixed
3c62694c31f043568c3f4784b8d247cc3bea6b4c
Fixed
5836a050d02e9598fa0f71e88dde28b63dfa35e3
Fixed
8f76277d02176cd739945bba3379448e2e22e799
Fixed
4407ff3af469356f9641c4a6e7072309bae86bea
Fixed
26560c4a03dc4d607331600c187f59ab2df5f341

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80599.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80599.json"