CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel's batman-adv module allows local users with eBPF TC hook access to exploit insufficient checks on packet sizes, potentially leading to out-of-bounds reads. This could compromise system stability or expose sensitive data. Organizations utilizing Linux systems with batman-adv should prioritize patching this vulnerability to mitigate risks associated with unauthorized access and data leakage.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX As documented in commit 8bd67ebb50c0 ("net: bridge: xmit: make sure we have at least eth header len bytes"), it is possible by for a local user with eBPF TC hook access to attach a tc filter which truncates the packet and redirects to an batadv interface. But the code assumes that at least ETH_HLEN bytes are available and thus might read outside of the available buffer. The batadv_interface_tx() must therefore always check itself if enough data is available for the ethernet header and don't rely on min_header_len.