AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72232

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's batman-adv module allows local users with eBPF TC hook access to exploit insufficient checks on packet sizes, potentially leading to out-of-bounds reads. This could compromise system stability or expose sensitive data. Organizations utilizing Linux systems with batman-adv should prioritize patching this vulnerability to mitigate risks associated with unauthorized access and data leakage.

CVE
CVE-2026-72232
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a local user with eBPF TC hook access to attach a tc filter which truncates the packet and redirects to an batadv interface. But the code assumes that at least ETH_HLEN bytes are available and thus might read outside of the available buffer. The batadv_interface_tx() must therefore always check itself if enough data is available for the ethernet header and don't rely on min_header_len.