← back
CVE-2026-53266highunder attackCWE-787

netfilter: bridge: make ebt_snat ARP rewrite writable

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 0.6%
from disclosure to weapon87 days
Published on NVDJun 25
1st PoC+87d
CISA KEV+85d
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
3 products (99 components)
Red Hat Enterprise Linux 10 · Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux for NVIDIA 26
workaround: Disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces.
Fixed
9 products (453 components)
Red Hat Enterprise Linux BaseOS (v. 9) · Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux Real Time (v. 9) · Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · and others 4
Not affected
2 products (42 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 6
Action required by CISAfederal deadline: 2026-09-21

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

A vulnerability in Linux kernel's netfilter bridge SNAT allows writing to non-writable memory regions in network packets. This can cause kernel crashes or memory corruption when processing certain ARP packets, especially those split across multiple memory fragments.

Technical detail

CVE-2026-53266 is a buffer write vulnerability (CWE-787) in netfilter's ebt_snat ARP rewrite function. The vulnerability occurs when skb_store_bits() writes to the ARP sender hardware address field without first ensuring the memory region is writable, particularly in non-linear skb fragments backed by splice-imported pages. An attacker can craft malicious ARP packets to trigger memory corruption or denial of service.

Summary generated and translated by AI from the official description.
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Linux · Linux
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.