{"id":"CVE-2026-89950","published":"2026-09-16T11:17:05.160","lastModified":"2026-09-16T11:17:05.160","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: mcast: linearize skbuff for packet generation\n\nbatadv_mcast_forw_packet() and batadv_mcast_forw_scrape() is not only\ncalled (indirectly) by the unsharing+linearizing batadv_recv_mcast_packet()\nhandler. When it is called (indirectly) by batadv_mcast_forw_mcsend() then\nit will be unshared but not linearized. The SKB_LINEAR_ASSERT() can\ntherefore cause a fatal BUG().\n\nThe linearization should happen during the expansion of the head because\nthe scrape function can be hit already during the initial\nbatadv_mcast_forw_mode() selection code:\n\n* batadv_interface_tx\n* batadv_mcast_forw_mode\n* batadv_mcast_forw_mode_by_count()\n* batadv_mcast_forw_push()\n  -> calls batadv_mcast_forw_expand_head() before everything else\n* batadv_mcast_forw_push_tvlvs()\n* batadv_mcast_forw_push_dests()\n* batadv_mcast_forw_push_adjust_padding()\n* batadv_mcast_forw_scrape()","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/2879177539e3ece483a8e5406970373698e9a6c5","tags":[]},{"url":"https://git.kernel.org/stable/c/6a30a59e2660afd03c975f1b8eae6a2301161197","tags":[]},{"url":"https://git.kernel.org/stable/c/a9603e0a7cb5e0cddc6b23af153cf7daafc5c55e","tags":[]},{"url":"https://git.kernel.org/stable/c/c32e5e25c41201c8c3b796a4ab2c45103187091e","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}