Impact
The reported issue occurs in the batman-adv data module of the Linux kernel, where it performs an unaligned memory access when extracting IP addresses from an ARP packet. On processors that do not support native unaligned reads, this access can trigger a fault, potentially leading the kernel to crash. Such a crash would result in a loss of network service on the affected host.
Affected Systems
The vulnerability affects all Linux kernel implementations that include batman-adv, regardless of distribution. No specific version list is supplied, but the defect was fixed by applying the upstream patch (commit 0121afa52cdb...) in the kernel tree. Hosts running batman-adv prior to that commit are vulnerable.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not currently listed in CISA’s KEV catalog, indicating a low exploitation likelihood. However, because an attacker can send crafted ARP messages over the network, the potential impact is remote denial of service that brings the kernel to an unreachable state. The CVSS score is not provided in the data, but the nature of a kernel crash suggests a high severity if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA