Description
In the Linux kernel, the following vulnerability has been resolved:

batman-adv: fix stale receive device on merged fragments

Fragment reassembly reuses the skb from the highest-numbered buffered
fragment as the merged packet. When that fragment was received on a hard
interface which is deleted before the chain completes, the merged skb can
re-enter the receive path with a stale skb->dev and skb_iif.

batadv_batman_skb_recv() passes such merged packets through the normal
receive handlers again. DAT and bridge loop avoidance both derive the ARP
header length from skb->dev, so they can dereference the freed net_device
before the packet reaches the local mesh interface.

Refresh the receive device metadata from the current receive device before
running the packet handlers. This keeps internally reinjected merged
fragments consistent with the normal receive path after hard interface
teardown.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash using crafted fragmented packets
Action: Immediate Patch
AI Analysis

Impact

Fragment reassembly in the Linux kernel’s batman‑adv module reuses the socket buffer (skb) from the last fragmented packet. If that fragment is received on a physical interface that is later removed before the reassembly chain completes, the skb can be reinjected with a stale device reference (skb->dev and skb_iif). When subsequent packet processing routines read this freed net_device pointer they dereference memory that no longer belongs to the kernel, leading to a crash and a local denial of service. The vulnerability is an uncontrolled use of freed memory that can destabilize the entire node ensuring the mesh remains unavailable while it restarts.

Affected Systems

All Linux distributions running a kernel that contains batman‑adv before the patch. This includes any system that has enabled mesh networking via batman‑adv and has not yet upgraded to a kernel that incorporates the latest batman‑adv merge‑fragment fix. No version range is specified, but the vulnerability exists in kernel releases that did not include the patch found in the commit referenced by the CVE description.

Risk and Exploitability

The CVE is scored 8.8 on CVSS, indicating a high severity. The EPSS score is below 1%, suggesting a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to send fragmented packets to a node running batman‑adv; the exact attack vector is inferred from the description and has not been reported in the wild. Monitoring for crafted fragmented traffic and applying the latest kernel update would mitigate the risk.

Generated by OpenCVE AI on September 18, 2026 at 07:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the batman‑adv merge‑fragment patch
  • If a timely update is unavailable, temporarily disable batman‑adv or unbind the mesh interfaces until the patch is applied
  • Verify that all NICs used by batman‑adv are properly functioning and that interface teardown is performed safely

Generated by OpenCVE AI on September 18, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged fragments Fragment reassembly reuses the skb from the highest-numbered buffered fragment as the merged packet. When that fragment was received on a hard interface which is deleted before the chain completes, the merged skb can re-enter the receive path with a stale skb->dev and skb_iif. batadv_batman_skb_recv() passes such merged packets through the normal receive handlers again. DAT and bridge loop avoidance both derive the ARP header length from skb->dev, so they can dereference the freed net_device before the packet reaches the local mesh interface. Refresh the receive device metadata from the current receive device before running the packet handlers. This keeps internally reinjected merged fragments consistent with the normal receive path after hard interface teardown.
Title batman-adv: fix stale receive device on merged fragments
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:34.244Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89951

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.267

Modified: 2026-09-16T15:18:19.990

Link: CVE-2026-89951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:05Z

Weaknesses