CVE-2026-53266
Linux Kernel Out-of-Bounds Write Vulnerability - [Actively Exploited]
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().
INFO
Published Date :
June 25, 2026, 9:16 a.m.
Last Modified :
Sept. 19, 2026, 4:17 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Unknown
This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Apply the Linux kernel patch for netfilter: bridge.
- Verify skb_ensure_writable() before ARP header modification.
- Confirm skb_store_bits() can write to the ARP SHA range.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53266.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53266 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53266
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53266 vulnerability anywhere in the article.
-
The Hacker News
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence o ... Read more
-
TheCyberThrone
CISA KEV Update: Three Linux Kernel Bugs, Acronis Backup and Google Pixel
September 18, 2026 — CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. Two additional vulnerabilities affecting Acronis Backup and Google Pixel were a ... Read more
The following table lists the changes that have been made to the
CVE-2026-53266 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 19, 2026
Action Type Old Value New Value Changed SSVC {'id': 'CVE-2026-53266', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-18T14:40:13.592810Z'} {'id': 'CVE-2026-53266', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-18T00:00:00+00:00'} -
Modified Analysis by [email protected]
Sep. 18, 2026
Action Type Old Value New Value Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266 Types: US Government Resource -
CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725
Sep. 18, 2026
Action Type Old Value New Value Added Date Added 2026-09-18 Added Due Date 2026-09-18 Added Required Action 2026-09-18 Added Vulnerability Name 2026-09-18 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 18, 2026
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266 Changed SSVC {'id': 'CVE-2026-53266', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-18T13:17:28.192271Z'} {'id': 'CVE-2026-53266', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-18T14:40:13.592810Z'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 18, 2026
Action Type Old Value New Value Added CWE CWE-787 Added SSVC {'id': 'CVE-2026-53266', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-18T13:17:28.192271Z'} -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 18, 2026
Action Type Old Value New Value Added Reference https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Added Reference https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Added Reference https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Added Reference https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Added Reference https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Added Reference https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Added Reference https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Added Reference https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 Removed Reference https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Removed Reference https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Removed Reference https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Removed Reference https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Removed Reference https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Removed Reference https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Removed Reference https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Removed Reference https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 Removed Reference Type https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Types: Patch Removed Reference Type https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Types: Patch Removed Reference Type https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Types: Patch Removed Reference Type https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Types: Patch Removed Reference Type https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Types: Patch Removed Reference Type https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Types: Patch Removed Reference Type https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Types: Patch Removed Reference Type https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 Types: Patch -
Initial Analysis by [email protected]
Jul. 08, 2026
Action Type Old Value New Value Added CWE NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.8.17 up to (excluding) 5.9 *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.4.73 up to (excluding) 5.5 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.9.2 up to (excluding) 5.10.259 Added Reference Type kernel.org: https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 28, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 25, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '76280b78cc9f23bdc6438e10ad6dff148ef8375b', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'b7e91939ba9be805a62a257fa4e227dffbb88fa0', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'afd64b59c3de9bbbdd3759e834fdc55cda716e0b', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '153ea96c806aea395daba907a4f88480b6ad5093', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'b18675263db1147c8e1cab625400c13a0d87bd2d', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '67ba971ae02514d85818fe0c32549ab4bfa3bf49', 'versionType': 'git'}, {'status': 'affected', 'version': '2f3839075a5f8dcf116c1abe35b36b018ac62445', 'versionType': 'git'}, {'status': 'affected', 'version': '51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7d23c2c87584eb429f115c078ed511be8b18e29', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.73', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.8.17', 'lessThan': '5.9', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.9.2', 'lessThan': '5.10', 'versionType': 'semver'}], 'programFiles': ['net/bridge/netfilter/ebt_snat.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.10'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.10', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bridge/netfilter/ebt_snat.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits(). Added Reference https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Added Reference https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Added Reference https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Added Reference https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Added Reference https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Added Reference https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Added Reference https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Added Reference https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5