CVE-2026-80601

Source
https://cve.org/CVERecord?id=CVE-2026-80601
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80601.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80601
Downstream
Published
2026-08-28T06:48:27.948Z
Modified
2026-08-30T03:48:09.401673480Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
batman-adv: gw: acquire ethernet header only after skb realloc
Details

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: gw: acquire ethernet header only after skb realloc

The pskbmaypull() called by batadvgetvid() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80601.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6c413b1c22a2c4ef324f1c6f2c282f1ca10a93b9
Fixed
2760b38222c8828b075802342fe3b91eb823d542
Fixed
6c37f1166549c999ccd164b0cb6462d1ae68f8f6
Fixed
b79884a5567bf788fb76c30832467cf6a56f3c0d
Fixed
afac8096bde4948e3caa7e4dd733867cfbd3018e
Fixed
e3f4325e35dd6e76b80665f3510738ce34819753
Fixed
e6b43acd34b219b807e65096ce207b087942779d
Fixed
916dac5f2944f63f07f7b501acbea6737dbbed0e
Fixed
77880a3be88d378d60cc1e8f8ec70430e2ed0518

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80601.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80601.json"