Impact
The batman‑adv module in the Linux kernel contains a flaw where certain multicast forwarding functions may operate on a socket buffer that is not fully linearized. Because the kernel uses a SKB_LINEAR_ASSERT check, an attacker can trigger a fatal BUG() when the buffer is still in a fragmented state. This fault leads to a kernel crash and the host being rebooted or halted; it does not grant code execution or privilege escalation, and therefore the principal impact is a denial of service. The weakness can be classified as CWE‑665: Improper Initialization.
Affected Systems
All Linux operating systems that ship a kernel with the batman‑adv (broadcast‑advanced) multicast forwarding code and have not applied the linearization patch are vulnerable. Distributions that include an unedited batman‑adv module in the kernel vendor branch, regardless of version, are at risk. The patch is available in recent kernel releases where the forwarding code ensures the skb is linearized before any operation.
Risk and Exploitability
The EPSS score is below 1 %, indicating that real‑world exploitation is considered unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of active exploitation. The likely attack vector is through the network; a malicious host can send specially crafted multicast packets that are processed by the batman‑adv module, causing the skb linearization assertion to fail. Because the flaw requires the batman‑adv module to be loaded and the attacker to generate multicast traffic, the attack is not trivial but is feasible by a remote actor with network access. The impact is limited to a kernel crash, which leads to service disruption rather than data exfiltration or elevation of privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA