CVE-2026-89949

Source
https://cve.org/CVERecord?id=CVE-2026-89949
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89949.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89949
Downstream
Published
2026-09-16T10:32:34Z
Modified
2026-09-18T03:48:34Z
Summary
batman-adv: dat: avoid unaligned fault in IP extraction
Details

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: avoid unaligned fault in IP extraction

Independent of the alignment of the ARP packet in the SKB, either the batadv_arp_ip_src or the batadv_arp_ip_dst will have an unaligned access (on HW without native unaligned read support).

Use get_unaligned() to handle this properly on all architectures.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89949.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5c3a0e5535933349a5d6e6bc8b704e0611f21d3f
Fixed
b1bbc694ca51adb8dbed3f3235b4fcbdb44e0e20
Fixed
15dbfb37f0e1a085d48deeb8f5238e9d28127dde
Fixed
a170d4617e8cca05a1314de61728a262ef272782
Fixed
c74a4acf41d19f21199dec2d6c813c90d31cd02c
Fixed
91c99b4e152023c7d458a5dedd52d2b0d7df4ce3
Fixed
1cfa7d5f70d54cb8c7e82df739430782d1996ee1
Fixed
0c2df865338bbf92aa45b9253e5f9b8ef2d9992f
Fixed
0121afa52cdb88cfb4d5d7bd126a23a9100121d8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89949.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89949.json"