Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-46198

CVE-2026-46198: Linux Kernel Buffer Overflow Vulnerability

CVE-2026-46198 is a buffer overflow flaw in the Linux kernel's batman-adv module caused by integer overflow in batadv_iv_ogm_send_to_if that may lead to out-of-bound reads. This article covers technical details, impact, and fixes.

Published:

CVE-2026-46198 Overview

CVE-2026-46198 is an integer overflow vulnerability in the Linux kernel's batman-adv (B.A.T.M.A.N. Advanced) mesh networking module. The flaw resides in the batadv_iv_ogm_send_to_if function, where the buff_pos variable is declared as an s16 (signed 16-bit integer), while the corresponding size check in batadv_iv_ogm_aggr_packet is performed using an int type. This type mismatch allows buff_pos to wrap around to a negative value, leading to an out-of-bounds read when the kernel processes Originator Messages (OGM) on the mesh interface.

Critical Impact

An attacker on the mesh network can craft aggregated OGM traffic that triggers an out-of-bounds kernel read, potentially leaking memory contents or destabilizing systems running batman-adv.

Affected Products

  • Linux kernel versions containing the batman-adv module prior to the upstream fixes
  • Distributions shipping batman-adv with the affected batadv_iv_ogm_send_to_if implementation
  • Mesh networking deployments using the B.A.T.M.A.N. IV routing algorithm

Discovery Timeline

  • 2026-05-28 - CVE-2026-46198 published to NVD
  • 2026-05-28 - Last updated in NVD database

Technical Details for CVE-2026-46198

Vulnerability Analysis

The batman-adv module implements a Layer 2 mesh routing protocol within the Linux kernel. It periodically transmits Originator Messages to advertise node presence and link quality across the mesh. To save bandwidth, batman-adv aggregates multiple OGM packets into a single transmission buffer and tracks the current write position using the buff_pos variable.

The vulnerability stems from inconsistent integer typing between the size validation and the position tracking. The validation function batadv_iv_ogm_aggr_packet evaluates the remaining buffer space using an int, while batadv_iv_ogm_send_to_if advances buff_pos using the narrower s16 type. When buff_pos increments past the s16 positive range (32767), it wraps to a negative value that still passes the int-based size check, allowing iteration to continue beyond the buffer boundary.

Root Cause

The root cause is a numeric type mismatch between a bounds check and the index used to traverse the aggregated packet buffer. The s16 declaration of buff_pos is the narrowing type. Once the position counter overflows, subsequent dereferences read memory outside the intended packet buffer.

Attack Vector

The vulnerability is reachable through the mesh network interface that processes batman-adv traffic. An adjacent attacker who can inject or relay crafted OGM frames into the mesh can drive the aggregation loop into the overflow condition. Successful exploitation yields an out-of-bounds read in kernel context, which can disclose adjacent kernel memory or cause instability.

No verified public proof-of-concept exploit is currently available. Technical specifics are documented in the upstream commits referenced in the Linux kernel stable tree.

Detection Methods for CVE-2026-46198

Indicators of Compromise

  • Unexpected kernel log entries referencing batman-adv, batadv_iv_ogm_send_to_if, or out-of-bounds access warnings from KASAN-enabled kernels.
  • Crashes or oops messages on systems running the batman-adv module after receiving malformed OGM aggregation traffic.
  • Anomalous OGM packet rates or oversized aggregated frames on mesh interfaces.

Detection Strategies

  • Inventory hosts that load the batman_adv kernel module using lsmod | grep batman and correlate against patched kernel versions.
  • Monitor kernel ring buffer output (dmesg) for warnings tied to batman-adv aggregation processing.
  • Capture and inspect mesh interface traffic for OGM frames whose cumulative aggregated length approaches or exceeds 32 KB.

Monitoring Recommendations

  • Enable kernel address sanitizer (KASAN) or CONFIG_DEBUG_KERNEL options in test environments to surface out-of-bounds reads during validation.
  • Forward kernel logs from mesh nodes to a centralized logging or SIEM pipeline for correlation across the mesh.
  • Track package and kernel versions of all mesh participants to confirm patch coverage.

How to Mitigate CVE-2026-46198

Immediate Actions Required

  • Apply the upstream kernel patches that align the buff_pos type with the size check used in batadv_iv_ogm_aggr_packet.
  • Update affected Linux distributions to the kernel build that incorporates the batman-adv fix once released by the vendor.
  • If patching is not immediately possible, restrict mesh interface participation to trusted nodes and reduce exposure of batman-adv to untrusted Layer 2 segments.

Patch Information

The fix is committed to the Linux kernel stable tree across multiple branches. Reference the following commits: 0799e594, 974542d1, b252797b, bf872db5, and f6149935. The patches correct the integer type used for buff_pos so the bounds check cannot be bypassed via signed overflow.

Workarounds

  • Unload the batman_adv module on systems that do not require mesh networking using modprobe -r batman_adv.
  • Blacklist the module in /etc/modprobe.d/ to prevent autoload on systems that should never run batman-adv.
  • Limit mesh participation to authenticated peers and segment mesh traffic away from untrusted networks until patches are deployed.
bash
# Blacklist batman-adv on systems that do not require it
echo "blacklist batman_adv" | sudo tee /etc/modprobe.d/disable-batman-adv.conf
sudo modprobe -r batman_adv
# Verify the module is no longer loaded
lsmod | grep batman_adv

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.