8.8
HIGH CVSS 3.1
CVE-2026-53266
netfilter: bridge: make ebt_snat ARP rewrite writable
Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

INFO

Published Date :

June 25, 2026, 9:16 a.m.

Last Modified :

July 8, 2026, 4:02 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-53266 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Ensure ARP SHA range is writable before modifying it.
  • Apply the Linux kernel patch for netfilter: bridge.
  • Verify skb_ensure_writable() before ARP header modification.
  • Confirm skb_store_bits() can write to the ARP SHA range.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-53266 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-53266 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-53266 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-53266 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jul. 08, 2026

    Action Type Old Value New Value
    Added CWE NVD-CWE-noinfo
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.8.17 up to (excluding) 5.9 *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.4.73 up to (excluding) 5.5 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.9.2 up to (excluding) 5.10.259
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 Types: Patch
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 28, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 25, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '76280b78cc9f23bdc6438e10ad6dff148ef8375b', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'b7e91939ba9be805a62a257fa4e227dffbb88fa0', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'afd64b59c3de9bbbdd3759e834fdc55cda716e0b', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '153ea96c806aea395daba907a4f88480b6ad5093', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'b18675263db1147c8e1cab625400c13a0d87bd2d', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '67ba971ae02514d85818fe0c32549ab4bfa3bf49', 'versionType': 'git'}, {'status': 'affected', 'version': '2f3839075a5f8dcf116c1abe35b36b018ac62445', 'versionType': 'git'}, {'status': 'affected', 'version': '51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7d23c2c87584eb429f115c078ed511be8b18e29', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.73', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.8.17', 'lessThan': '5.9', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.9.2', 'lessThan': '5.10', 'versionType': 'semver'}], 'programFiles': ['net/bridge/netfilter/ebt_snat.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.10'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.10', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bridge/netfilter/ebt_snat.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().
    Added Reference https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093
    Added Reference https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49
    Added Reference https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b
    Added Reference https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b
    Added Reference https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d
    Added Reference https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0
    Added Reference https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87
    Added Reference https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.