CVE-2026-53266
published 2026-06-25CVE-2026-53266: In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the…
PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet
payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check
the payload, not the Ethernet header, and would reintroduce the small
packet regression fixed by commit 63137bc5882a.
However, the optional ARP sender hardware address rewrite is different.
It writes through skb_store_bits() at an offset relative to skb->data:
skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)
skb_header_pointer() only safely reads the ARP header; it does not make
the later sender hardware address range writable. If that range is
still held in a nonlinear skb fragment backed by a splice-imported file
page, skb_store_bits() maps the frag page and copies the new MAC address
directly into it.
Ensure the ARP SHA range is writable before reading the ARP header and
before calling skb_store_bits().
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 5.4.73 < 5.5 | 5.5 |
| linux | linux | >= 5.8.17 < 5.9 | 5.9 |
| linux | linux | >= 5.9.2 < 5.10 | 5.10 |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 | bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < 76280b78cc9f23bdc6438e10ad6dff148ef8375b | 76280b78cc9f23bdc6438e10ad6dff148ef8375b |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < b7e91939ba9be805a62a257fa4e227dffbb88fa0 | b7e91939ba9be805a62a257fa4e227dffbb88fa0 |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < afd64b59c3de9bbbdd3759e834fdc55cda716e0b | afd64b59c3de9bbbdd3759e834fdc55cda716e0b |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < 153ea96c806aea395daba907a4f88480b6ad5093 | 153ea96c806aea395daba907a4f88480b6ad5093 |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < b18675263db1147c8e1cab625400c13a0d87bd2d | b18675263db1147c8e1cab625400c13a0d87bd2d |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 | c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 |
| linux | linux | >= 63137bc5882a1882c553d389fdeeeace86ee1741 < 67ba971ae02514d85818fe0c32549ab4bfa3bf49 | 67ba971ae02514d85818fe0c32549ab4bfa3bf49 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.11 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 5.4.73 < 5.5 | 5.5 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: netfilter: bridge: make ebt_snat ARP rewrite writable
vendor_redhat·2026-06-25·CVSS 8.8
CVE-2026-53266 [HIGH] kernel: netfilter: bridge: make ebt_snat ARP rewrite writable
kernel: netfilter: bridge: make ebt_snat ARP rewrite writable
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet
payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check
the payload, not the Ethernet header, and would reintroduce the small
packet regression fixed by commit 63137bc5882a.
However, the optional ARP sender hardware address rewrite is different.
It writes through skb_store_bits() at an offset relative to skb->data:
skb_store_bits(skb, size
GHSA
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind sk
ghsa_unreviewed·2026-06-25
CVE-2026-53266 In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind sk
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet
payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check
the payload, not the Ethernet header, and would reintroduce the small
packet regression fixed by commit 63137bc5882a.
However, the optional ARP sender hardware address rewrite is different.
It writes through skb_store_bits() at an offset relative to skb->data:
skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)
skb_header_pointer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53266 kernel: netfilter: bridge: make ebt_snat ARP rewrite writable
bugzilla·2026-06-25·CVSS 8.8
CVE-2026-53266 [HIGH] CVE-2026-53266 kernel: netfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-53266 kernel: netfilter: bridge: make ebt_snat ARP rewrite writable
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet
payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check
the payload, not the Ethernet header, and would reintroduce the small
packet regression fixed by commit 63137bc5882a.
However, the optional ARP sender hardware address rewrite is different.
It writes through skb_store_bits() at an offset relative to skb->data:
skb_s
Bugzilla
CVE-2026-53266 kernel: Linux kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite
bugzilla·2026-06-05·CVSS 8.8
CVE-2026-53266 [HIGH] CVE-2026-53266 kernel: Linux kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite
CVE-2026-53266 kernel: Linux kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite
A flaw in the Linux kernel's ebtables SNAT target allows writing to shared memory pages when rewriting ARP sender hardware addresses without ensuring writability, potentially causing file/memory corruption or denial of service.
Discussion:
A memory corruption flaw was found in the Linux kernel's netfilter subsystem
in the ebtables SNAT (Source Network Address Translation) target. When
rewriting the ARP sender hardware address (SHA), the code fails to ensure
the target memory region is writable before modification. The vulnerable
code path uses skb_header_pointer() to read the ARP header, which only
provides safe read access, followed by skb_store_bits()
https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375bhttps://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0bhttps://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2dhttps://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
2026-06-25
Published