CVE-2026-80600

Source
https://cve.org/CVERecord?id=CVE-2026-80600
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80600.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80600
Downstream
Published
2026-08-28T06:48:27.351Z
Modified
2026-08-29T03:46:57.994465597Z
Summary
batman-adv: dat: acquire ARP hw source only after skb realloc
Details

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: acquire ARP hw source only after skb realloc

The pskbmaypull() called by batadvgetvid() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80600.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b61ec31c85756bbc898fb892555509afe709459a
Fixed
a82fc217cb7a447313c76ebf9f09b100771b0ddf
Fixed
86aa79b43e5b561fd3648891165bd7313b541315
Fixed
d755cd001fa2c248e186c1fc3df3d11d97dc843c
Fixed
3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146
Fixed
01678c53a7717a748aee388b6839e7b9761d641c
Fixed
3b4c70c40f2e135a50cd38fc61c7d23a296a9981
Fixed
059a70e1d12d6d99310e0599d37b0323557569a8
Fixed
48067b2ae4504500a7093d9e1e16b42e70330480

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80600.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80600.json"