Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: avoid unaligned fault in IP extraction

Independent of the alignment of the ARP packet in the SKB, either the
batadv_arp_ip_src or the batadv_arp_ip_dst will have an unaligned access
(on HW without native unaligned read support).

Use get_unaligned() to handle this properly on all architectures.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Apply Patch
AI Analysis

Impact

The reported issue occurs in the batman-adv data module of the Linux kernel, where it performs an unaligned memory access when extracting IP addresses from an ARP packet. On processors that do not support native unaligned reads, this access can trigger a fault, potentially leading the kernel to crash. Such a crash would result in a loss of network service on the affected host.

Affected Systems

The vulnerability affects all Linux kernel implementations that include batman-adv, regardless of distribution. No specific version list is supplied, but the defect was fixed by applying the upstream patch (commit 0121afa52cdb...) in the kernel tree. Hosts running batman-adv prior to that commit are vulnerable.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not currently listed in CISA’s KEV catalog, indicating a low exploitation likelihood. However, because an attacker can send crafted ARP messages over the network, the potential impact is remote denial of service that brings the kernel to an unreachable state. The CVSS score is not provided in the data, but the nature of a kernel crash suggests a high severity if exploited.

Generated by OpenCVE AI on September 18, 2026 at 07:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the batman-adv patch (e.g., commit 0121afa52cdb...), which replaces unsafe memory accesses with get_unaligned().
  • If an immediate kernel update is not possible, stop or disable the batman-adv networking service until the fix is deployed to prevent reception of harmful ARP packets.
  • Monitor network traffic for malformed ARP packets and ensure that network devices do not generate or forward them during the transition period.

Generated by OpenCVE AI on September 18, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-673

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: avoid unaligned fault in IP extraction Independent of the alignment of the ARP packet in the SKB, either the batadv_arp_ip_src or the batadv_arp_ip_dst will have an unaligned access (on HW without native unaligned read support). Use get_unaligned() to handle this properly on all architectures.
Title batman-adv: dat: avoid unaligned fault in IP extraction
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:34.794Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.030

Modified: 2026-09-16T11:17:05.030

Link: CVE-2026-89949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:05Z

Weaknesses
  • CWE-673

    External Influence of Sphere Definition