Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-53266— netfilter: bridge: make ebt_snat ARP rewrite writable

Quick assessment

Affected
Linux Linux
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 5.4.73至5.5之前版本存在安全漏洞,该漏洞源于ARP发送者硬件地址范围不可写,可能导致skb_store_bits函数在非线性skb片段中直接写入页面,从而可能导致信息泄露或系统不稳定。

CVSS 8.8 · High KEV EPSS 0.83% · P56

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 24

VendorProduct Version RangeStatus
Linux Linux 63137bc5882a1882c553d389fdeeeace86ee1741< bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 affected
63137bc5882a1882c553d389fdeeeace86ee1741< 76280b78cc9f23bdc6438e10ad6dff148ef8375b affected
63137bc5882a1882c553d389fdeeeace86ee1741< b7e91939ba9be805a62a257fa4e227dffbb88fa0 affected
63137bc5882a1882c553d389fdeeeace86ee1741< afd64b59c3de9bbbdd3759e834fdc55cda716e0b affected
63137bc5882a1882c553d389fdeeeace86ee1741< 153ea96c806aea395daba907a4f88480b6ad5093 affected
63137bc5882a1882c553d389fdeeeace86ee1741< b18675263db1147c8e1cab625400c13a0d87bd2d affected
63137bc5882a1882c553d389fdeeeace86ee1741< c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5 affected
63137bc5882a1882c553d389fdeeeace86ee1741< 67ba971ae02514d85818fe0c32549ab4bfa3bf49 affected
… +16 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53266

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: bridge: make ebt_snat ARP rewrite writable
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 5.4.73至5.5之前版本存在安全漏洞,该漏洞源于ARP发送者硬件地址范围不可写,可能导致skb_store_bits函数在非线性skb片段中直接写入页面,从而可能导致信息泄露或系统不稳定。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 63137bc5882a1882c553d389fdeeeace86ee1741 ~ bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87 -
Linux Linux 5.10 -

II. Public POCs for CVE-2026-53266

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53266

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-53266 (8)

Same Patch Batch · Linux · 2026-06-25 · 146 CVEs total

CVE-2026-53247 9.8 CRITICAL net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
CVE-2026-53175 9.8 CRITICAL inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
CVE-2026-53176 9.8 CRITICAL IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
CVE-2026-53228 9.8 CRITICAL ipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-53221 9.8 CRITICAL ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
CVE-2026-53246 9.8 CRITICAL sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVE-2026-53151 9.8 CRITICAL rxrpc: Fix the ACK parser to extract the SACK table for parsing
CVE-2026-53260 9.8 CRITICAL tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
CVE-2026-53216 9.8 CRITICAL net: mvpp2: limit XDP frame size to the RX buffer
CVE-2026-53215 9.8 CRITICAL net: mvpp2: refill RX buffers before XDP or skb use
CVE-2026-53131 9.4 CRITICAL netfilter: require Ethernet MAC header before using eth_hdr()
CVE-2026-53225 9.1 CRITICAL sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-53186 9.1 CRITICAL RDMA/srp: bound SRP_RSP sense copy by the received length
CVE-2026-53224 9.1 CRITICAL sctp: validate embedded INIT chunk and address list lengths in cookie
CVE-2026-53277 8.8 HIGH KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
CVE-2026-53198 8.8 HIGH ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
CVE-2026-53159 8.8 HIGH misc: fastrpc: fix DMA address corruption due to find_vma misuse
CVE-2026-53240 8.8 HIGH xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
CVE-2026-53188 8.8 HIGH RDMA/core: Validate the passed in fops for ib_get_ucaps()
CVE-2026-53275 8.8 HIGH ipv6: mcast: Fix use-after-free when processing MLD queries

Showing top 20 of 146 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-53266

No comments yet


Leave a comment