netfilter: bridge: make ebt_snat ARP rewrite writable
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A vulnerability in Linux kernel's netfilter bridge SNAT allows writing to non-writable memory regions in network packets. This can cause kernel crashes or memory corruption when processing certain ARP packets, especially those split across multiple memory fragments.
CVE-2026-53266 is a buffer write vulnerability (CWE-787) in netfilter's ebt_snat ARP rewrite function. The vulnerability occurs when skb_store_bits() writes to the ARP sender hardware address field without first ensuring the memory region is writable, particularly in non-linear skb fragments backed by splice-imported pages. An attacker can craft malicious ARP packets to trigger memory corruption or denial of service.