PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80599 Linux CVE debrief

The CVE-2026-80599 vulnerability is an out-of-bounds access issue in the batman-adv module of the Linux kernel. This issue arises when the batadv_get_vid() function accesses the proto field of the ethernet header without ensuring the data is accessible. The caller is responsible for this check, but batadv_dat_get_vid() and its caller did not perform this verification. This could potentially lead to an out-of-bounds access. Linux kernel users and administrators, especially those using the batman-adv module, should be aware of this vulnerability and take necessary actions to mitigate potential risks. The CVE has a CVSS score of 8.1 and is classified as HIGH severity.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-08-29
Advisory published
2026-08-28
Advisory updated
2026-08-29

Who should care

Linux kernel users and administrators, especially those using the batman-adv module, should be aware of this vulnerability and take necessary actions to mitigate potential risks. This includes verifying Linux kernel and batman-adv module versions for CVE-2026-80599 compliance, updating the batman-adv module to the latest version, and reviewing system configurations for potential exposure. Linux kernel users should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Additionally, they should track exceptions, retest remediated assets, and close the item only after evidence is documented. System administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential out-of-bounds access issues in the batman-adv module of the Linux kernel. They should also consider the operational impact of this vulnerability and take steps to minimize potential disruptions. Furthermore, Linux kernel users and administrators should ensure that their systems are configured securely and that they have implemented necessary security measures to prevent exploitation of this vulnerability. They should also stay informed about any updates or patches related to this vulnerability and apply them promptly to prevent potential attacks. Linux kernel users and administrators can also consider implementing additional security controls, such as monitoring and detection systems, to help identify and respond to potential security incidents related to this vulnerability. By taking these steps, Linux kernel users and administrators can help protect their systems from potential out-of-bounds access issues and ensure the security and integrity of their systems. Linux kernel users and administrators should also review their incident response plans and ensure that they are prepared to respond to potential security incidents related to this vulnerability. They should also consider conducting regular security audits and risk assessments to identify and mitigate potential security risks related to this vulnerability. Linux '

Technical summary

The CVE-2026-80599 vulnerability is caused by the batadv_get_vid() function accessing the proto field of the ethernet header without ensuring the data is accessible. The issue is in the batman-adv module of the Linux kernel. The CVE has a CVSS score of 8.1 and is classified as HIGH severity. Linux kernel users should verify their systems are updated with the latest batman-adv module to mitigate potential out-of-bounds access issues.

Defensive priority

Linux kernel users should verify their systems are updated with the latest batman-adv module to mitigate potential out-of-bounds access issues.

Recommended defensive actions

  • Verify Linux kernel and batman-adv module versions for CVE-2026-80599 compliance
  • Update the batman-adv module to the latest version
  • Review system configurations for potential exposure
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE-2026-80599 vulnerability involves an out-of-bounds access issue in the batman-adv module of the Linux kernel. The issue arises from the batadv_get_vid() function accessing the proto field of the ethernet header without ensuring the data is accessible. According to the source, the caller is responsible for this check, but batadv_dat_get_vid() and its caller did not perform this verification. This could potentially lead to an out-of-bounds access. The CVE has a CVSS score of 8.1 and is classified as HIGH severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80599 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80599

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80599 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80599

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/26560c4a03dc4d607331600c187f59ab2df5f341

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3c62694c31f043568c3f4784b8d247cc3bea6b4c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4407ff3af469356f9641c4a6e7072309bae86bea

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5836a050d02e9598fa0f71e88dde28b63dfa35e3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6d3ea37074bb747f745d28138f87745ba9bd97c5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7913935d41f166c367bbf7cc76a79e50044388e8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8f76277d02176cd739945bba3379448e2e22e799

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/da3677b5ed362742d30ceab31bfafcdc74dc2642

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.