CVE-2026-80599

Updated on 28 Aug 2026

Severity

8.1 High severity

Details

CVSS score
8.1
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: ensure accessible eth_hdr proto field

When batadv_get_vid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. But in contrast to other call sites, batadv_dat_get_vid() and its caller didn’t make sure this is true. This could have caused an out-of-bounds access.

Details

Affected packages:
linux @ 5.10.259 (+4 more)

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Oracle Linux 9 UEK 7 Planned