CVE-2026-53266
netfilter: bridge: make ebt_snat ARP rewrite writable
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().
INFO
Published Date :
June 25, 2026, 9:16 a.m.
Last Modified :
July 8, 2026, 4:02 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Apply the Linux kernel patch for netfilter: bridge.
- Verify skb_ensure_writable() before ARP header modification.
- Confirm skb_store_bits() can write to the ARP SHA range.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53266.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53266 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53266
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53266 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53266 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 08, 2026
Action Type Old Value New Value Added CWE NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.8.17 up to (excluding) 5.9 *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.4.73 up to (excluding) 5.5 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.9.2 up to (excluding) 5.10.259 Added Reference Type kernel.org: https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 28, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 25, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '76280b78cc9f23bdc6438e10ad6dff148ef8375b', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'b7e91939ba9be805a62a257fa4e227dffbb88fa0', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'afd64b59c3de9bbbdd3759e834fdc55cda716e0b', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '153ea96c806aea395daba907a4f88480b6ad5093', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'b18675263db1147c8e1cab625400c13a0d87bd2d', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': 'c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5', 'versionType': 'git'}, {'status': 'affected', 'version': '63137bc5882a1882c553d389fdeeeace86ee1741', 'lessThan': '67ba971ae02514d85818fe0c32549ab4bfa3bf49', 'versionType': 'git'}, {'status': 'affected', 'version': '2f3839075a5f8dcf116c1abe35b36b018ac62445', 'versionType': 'git'}, {'status': 'affected', 'version': '51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b', 'versionType': 'git'}, {'status': 'affected', 'version': 'b7d23c2c87584eb429f115c078ed511be8b18e29', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.73', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.8.17', 'lessThan': '5.9', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.9.2', 'lessThan': '5.10', 'versionType': 'semver'}], 'programFiles': ['net/bridge/netfilter/ebt_snat.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.10'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.10', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bridge/netfilter/ebt_snat.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits(). Added Reference https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093 Added Reference https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 Added Reference https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b Added Reference https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b Added Reference https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d Added Reference https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0 Added Reference https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 Added Reference https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5