KernelScan.io

HIGH Introduced in 3.13

batman-adv TVLV ContainerSize Overflow

CVE-2026-52934

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.7HIGH

01

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_append() builds a TVLV packet section from the tvlv.container_list. The total size of this section is computed by batadv_tvlv_container_list_size(), which sums the sizes of all registered containers. The return type and accumulator in batadv_tvlv_container_list_size() were u16. If the accumulated size exceeds U16_MAX, the value wraps around, causing the subsequent allocation in batadv_tvlv_container_ogm_append() to be undersized. The memcpy-style copy that follows would then write beyond the end of the allocated buffer, corrupting kernel memory. Fix this by widening the return type of batadv_tvlv_container_list_size() to size_t. In batadv_tvlv_container_ogm_append(), check the computed length against U16_MAX before proceeding, and bail out as if the allocation had failed when the limit is exceeded.

02

Engine v0.3.0

Risk summary

An unprivileged local user or process can leverage user namespaces to obtain CAP_NET_ADMIN and register enough TVLV containers in the batman-adv mesh networking subsystem to cause a u16 integer overflow in the size accumulator. This results in an undersized heap allocation followed by an out-of-bounds write that corrupts kernel memory, leading to privilege escalation, arbitrary code execution in kernel context, or a kernel panic. The vulnerability has existed since Linux 3.13 and affects all kernels up to the fixed versions.

Affectednet/batman-adv/tvlv.c (batman-adv mesh networking TVLV subsystem)

Vulnerability analysis

The root cause is an integer overflow in batadv_tvlv_container_list_size(), which accumulated the total size of registered TVLV containers into a u16 variable. If the sum exceeds U16_MAX (65535 bytes), the accumulator wraps around. This wrapped value is used in batadv_tvlv_container_ogm_append() to allocate a packet buffer via batadv_tvlv_realloc_packet_buff(). The subsequent loop copies each container's data into the buffer using the actual (unwrapped) sizes, writing far beyond the end of the undersized allocation and corrupting kernel heap memory. The fix widens the return type and accumulator from u16 to size_t and adds an explicit U16_MAX check before allocation, bailing out with -E2BIG if exceeded. On default kernels, CAP_NET_ADMIN can be acquired by an unprivileged user through a user namespace, making the realistic actor an unprivileged local process or container tenant.

03

BranchIntroducedFixed inPatch commit
5.153.135.15.2101595628a2f87
6.13.136.1.1766448a49344e8
6.63.136.6.14313493b00dd1e
6.123.136.12.9394db72e9dac2
7.03.137.0.1194a3d72cd9b2
5.103.135.10.259c02aa6c0c9d1
6.183.136.18.34ede47988ac56
mainline3.137.1f50487e35663