Impact
Fragment reassembly in the Linux kernel’s batman‑adv module reuses the socket buffer (skb) from the last fragmented packet. If that fragment is received on a physical interface that is later removed before the reassembly chain completes, the skb can be reinjected with a stale device reference (skb->dev and skb_iif). When subsequent packet processing routines read this freed net_device pointer they dereference memory that no longer belongs to the kernel, leading to a crash and a local denial of service. The vulnerability is an uncontrolled use of freed memory that can destabilize the entire node ensuring the mesh remains unavailable while it restarts.
Affected Systems
All Linux distributions running a kernel that contains batman‑adv before the patch. This includes any system that has enabled mesh networking via batman‑adv and has not yet upgraded to a kernel that incorporates the latest batman‑adv merge‑fragment fix. No version range is specified, but the vulnerability exists in kernel releases that did not include the patch found in the commit referenced by the CVE description.
Risk and Exploitability
The CVE is scored 8.8 on CVSS, indicating a high severity. The EPSS score is below 1%, suggesting a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to send fragmented packets to a node running batman‑adv; the exact attack vector is inferred from the description and has not been reported in the wild. Monitoring for crafted fragmented traffic and applying the latest kernel update would mitigate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA