← Back to search

CVE-2026-89951

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-16

AI risk analysis

Summary
This vulnerability in the batman-adv module of the Linux kernel allows for potential data corruption and denial of service when handling fragmented packets, especially after a hard interface deletion.
Exploitability
Exploitation requires the attacker to send fragmented packets to a target system with a deleted hard interface, making it moderately difficult and dependent on specific network conditions.
Blast radius
If exploited, the vulnerability could lead to data corruption, bridge loop issues, and potential denial of service for the affected network segment.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the Linux kernel version 6.1.15 or later.
dosnetworkkernel

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged fragments Fragment reassembly reuses the skb from the highest-numbered buffered fragment as the merged packet. When that fragment was received on a hard interface which is deleted before the chain completes, the merged skb can re-enter the receive path with a stale skb->dev and skb_iif. batadv_batman_skb_recv() passes such merged packets through the normal receive handlers again. DAT and bridge loop avoidance both derive the ARP header length from skb->dev, so they can dereference the freed net_device before the packet reaches the local mesh interface. Refresh the receive device metadata from the current receive device before running the packet handlers. This keeps internally reinjected merged fragments consistent with the normal receive path after hard interface teardown.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.