Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: mcast: linearize skbuff for packet generation

batadv_mcast_forw_packet() and batadv_mcast_forw_scrape() is not only
called (indirectly) by the unsharing+linearizing batadv_recv_mcast_packet()
handler. When it is called (indirectly) by batadv_mcast_forw_mcsend() then
it will be unshared but not linearized. The SKB_LINEAR_ASSERT() can
therefore cause a fatal BUG().

The linearization should happen during the expansion of the head because
the scrape function can be hit already during the initial
batadv_mcast_forw_mode() selection code:

* batadv_interface_tx
* batadv_mcast_forw_mode
* batadv_mcast_forw_mode_by_count()
* batadv_mcast_forw_push()
-> calls batadv_mcast_forw_expand_head() before everything else
* batadv_mcast_forw_push_tvlvs()
* batadv_mcast_forw_push_dests()
* batadv_mcast_forw_push_adjust_padding()
* batadv_mcast_forw_scrape()
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The batman‑adv module in the Linux kernel contains a flaw where certain multicast forwarding functions may operate on a socket buffer that is not fully linearized. Because the kernel uses a SKB_LINEAR_ASSERT check, an attacker can trigger a fatal BUG() when the buffer is still in a fragmented state. This fault leads to a kernel crash and the host being rebooted or halted; it does not grant code execution or privilege escalation, and therefore the principal impact is a denial of service. The weakness can be classified as CWE‑665: Improper Initialization.

Affected Systems

All Linux operating systems that ship a kernel with the batman‑adv (broadcast‑advanced) multicast forwarding code and have not applied the linearization patch are vulnerable. Distributions that include an unedited batman‑adv module in the kernel vendor branch, regardless of version, are at risk. The patch is available in recent kernel releases where the forwarding code ensures the skb is linearized before any operation.

Risk and Exploitability

The EPSS score is below 1 %, indicating that real‑world exploitation is considered unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of active exploitation. The likely attack vector is through the network; a malicious host can send specially crafted multicast packets that are processed by the batman‑adv module, causing the skb linearization assertion to fail. Because the flaw requires the batman‑adv module to be loaded and the attacker to generate multicast traffic, the attack is not trivial but is feasible by a remote actor with network access. The impact is limited to a kernel crash, which leads to service disruption rather than data exfiltration or elevation of privileges.

Generated by OpenCVE AI on September 17, 2026 at 23:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the batman‑adv patch that ensures skb linearization before processing.
  • If an immediate kernel upgrade cannot be performed, disable the batman‑adv module or turn off multicast forwarding on the affected host to avoid the fault.
  • Continuously monitor kernel logs for BUG() entries or kernel panic messages and apply subsequent security updates when available.

Generated by OpenCVE AI on September 17, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: linearize skbuff for packet generation batadv_mcast_forw_packet() and batadv_mcast_forw_scrape() is not only called (indirectly) by the unsharing+linearizing batadv_recv_mcast_packet() handler. When it is called (indirectly) by batadv_mcast_forw_mcsend() then it will be unshared but not linearized. The SKB_LINEAR_ASSERT() can therefore cause a fatal BUG(). The linearization should happen during the expansion of the head because the scrape function can be hit already during the initial batadv_mcast_forw_mode() selection code: * batadv_interface_tx * batadv_mcast_forw_mode * batadv_mcast_forw_mode_by_count() * batadv_mcast_forw_push() -> calls batadv_mcast_forw_expand_head() before everything else * batadv_mcast_forw_push_tvlvs() * batadv_mcast_forw_push_dests() * batadv_mcast_forw_push_adjust_padding() * batadv_mcast_forw_scrape()
Title batman-adv: mcast: linearize skbuff for packet generation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:35.485Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89950

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.160

Modified: 2026-09-16T11:17:05.160

Link: CVE-2026-89950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:30:17Z

Weaknesses

No weakness.