In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error batadv_dat_forward_data() calls pskb_copy_for_clone() to duplicate an skb for each DHT candidate, but does not check the return value before passing it to batadv_send_skb_prepare_unicast_4addr(). That function dereferences the skb unconditionally, so a failed allocation triggers a NULL pointer dereference. Skip forwarding to the current DHT candidate on allocation failure.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 7.5 | High | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | <= 18.5 MR4 |
| Linux | Linux | <= 19.0 MR1 |
| Linux | Linux | Aruba InstantOS 8.6.x: 8.6.0.18 and below |
| Linux | Linux | 2023.3.0.23028 |