← voltar
CVE-2026-53266highsob ataqueCWE-787

netfilter: bridge: make ebt_snat ARP rewrite writable

71Vexday Risk Score

Priorize a correção. Ela está sob exploração confirmada pelo CISA e tem prova de conceito pública.

ssvc Actcvss 8.8epss 0.6%
da publicação à arma87 dias
Publicada no NVD25 de jun.
1ª PoC+87d
CISA KEV+85d
probabilidade de exploração
0.6%top 51% das CVEs
exploração observada
simCISA + VulnCheck
2 exploit(s) público(s)
O que os fabricantes declaram (VEX)

Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.

Afetado
3 produtos (99 componentes)
Red Hat Enterprise Linux 10 · Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux for NVIDIA 26
workaround: Disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces.
Corrigido
9 produtos (453 componentes)
Red Hat Enterprise Linux BaseOS (v. 9) · Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux Real Time (v. 9) · Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · e outros 4
Não afetado
2 produtos (42 componentes) — porque o código vulnerável não está presente no produto
Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 6
Ação exigida pela CISAprazo federal: 2026-09-21

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Em resumo

Uma falha no kernel do Linux permite escrever em áreas de memória não-graváveis em pacotes de rede. Isso pode causar travamento do kernel ou corrupção de memória ao processar certos pacotes ARP, especialmente aqueles divididos em múltiplos fragmentos de memória.

Detalhe técnico

CVE-2026-53266 é uma vulnerabilidade de escrita em buffer (CWE-787) na função de reescrita ARP do ebt_snat do netfilter. A falha ocorre quando skb_store_bits() escreve no campo de endereço hardware do remetente ARP sem antes garantir que a região de memória seja gravável, particularmente em fragmentos skb não-lineares apoiados por páginas importadas via splice. Um atacante pode criar pacotes ARP maliciosos para disparar corrupção de memória ou negação de serviço.

Resumo gerado e traduzido por IA a partir da descrição oficial.
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
Linux · Linux
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.