Researchers extended Syzkaller with a Syzlang grammar for crafted Ethernet frames to fuzz previously uncovered packet-reception paths in Linux’s batman-adv mesh-networking subsystem, particularly code in routing.c that had received no Syzbot coverage. The approach follows established work on exposing kernel networking interfaces to external-input fuzzing and targets protocol parsers reachable through network traffic rather than only local syscall surfaces.
The campaign identified three defects: a 16-bit integer overflow in OGM fragmentation, a use-after-free race in the throughput-meter path during interface deletion, and a TT TVLV VLAN-length truncation that can produce an out-of-bounds read. The researchers’ overflow fix has been merged into Linux mainline, while patches for the use-after-free were already circulating on kernel mailing lists; organizations using batman-adv should track kernel updates and prioritize remediation as fixes become available.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers identified an issue in batadv_tt_tvlv_unicast_handler_v1 where a VLAN-data size can be truncated when assigned to the 16-bit tt_vlan_len variable. The underestimated length can lead to an out-of-bounds read.
The fuzzing work identified a slab use-after-free race in which a batman-adv throughput-meter kernel thread can access mesh-interface data after its interface is deleted. The issue was already known and patches had been posted to Linux kernel mailing lists.
Researchers identified a signed 16-bit buff_pos overflow in batadv_iv_ogm_send_to_if that could bypass packet-length validation during OGM fragmentation. They submitted a fix widening the variable to signed 32-bit, and it was merged into Linux mainline.
Researchers found that the batman-adv routing.c path had no Syzbot coverage, then modified Syzkaller and added Syzlang Ethernet-frame packet definitions to exercise batman-adv reception logic.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.