CVE-2026-89951
8.8 HIGHPublished 2026-09-16 · Updated 2026-09-16
AI risk analysis
- Summary
- This vulnerability in the batman-adv module of the Linux kernel allows for potential data corruption and denial of service when handling fragmented packets, especially after a hard interface deletion.
- Exploitability
- Exploitation requires the attacker to send fragmented packets to a target system with a deleted hard interface, making it moderately difficult and dependent on specific network conditions.
- Blast radius
- If exploited, the vulnerability could lead to data corruption, bridge loop issues, and potential denial of service for the affected network segment.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the Linux kernel version 6.1.15 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged fragments Fragment reassembly reuses the skb from the highest-numbered buffered fragment as the merged packet. When that fragment was received on a hard interface which is deleted before the chain completes, the merged skb can re-enter the receive path with a stale skb->dev and skb_iif. batadv_batman_skb_recv() passes such merged packets through the normal receive handlers again. DAT and bridge loop avoidance both derive the ARP header length from skb->dev, so they can dereference the freed net_device before the packet reaches the local mesh interface. Refresh the receive device metadata from the current receive device before running the packet handlers. This keeps internally reinjected merged fragments consistent with the normal receive path after hard interface teardown.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
All references
- https://git.kernel.org/stable/c/2dffc8c44b6e3347b3719c6419c07b4a18fea895
- https://git.kernel.org/stable/c/63d86250fa7cbe22451369bd1c0881dfc8190958
- https://git.kernel.org/stable/c/6df64825f8b199921120c685af2abca14b077331
- https://git.kernel.org/stable/c/a2c272da99c2077088083c14961cf2f1e4506995
- https://git.kernel.org/stable/c/ad46c907d7d9975a285c1e89a4adde652eaa93f5
- https://git.kernel.org/stable/c/e91d2cc7441d89a45bad73ad9789159c7441cb80
- https://git.kernel.org/stable/c/f4b4ae763b5d59319fad62a00c76676758e7dafa
- https://git.kernel.org/stable/c/f830c2dfc1431764db9256b3d5db1695fc9a7f56
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-90104
- CRITICALCVE-2026-100075
- HIGHCVE-2026-11375
- HIGHCVE-2026-11381
- HIGHCVE-2026-11725
- HIGHCVE-2026-64562
- CRITICALCVE-2026-64564
- HIGHCVE-2026-64575
Related by shared AI tags and CWE weakness class. Browse the full archive.