Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-53266

netfilter: bridge: make ebt_snat ARP rewrite writable
Back to all
CVE

CVE-2026-53266

netfilter: bridge: make ebt_snat ARP rewrite writable

In the Linux kernel, the following vulnerability has been resolved:

netfilter: bridge: make ebt_snat ARP rewrite writable

The ebtables SNAT target keeps the Ethernet source address rewrite

behind skbensurewritable(skb, 0).  This is intentional: at the bridge

ebtables hooks the Ethernet header is addressed through

skbmacheader()/eth_hdr(), while skb->data points at the Ethernet

payload.  Asking skbensurewritable() for ETH_HLEN bytes would check

the payload, not the Ethernet header, and would reintroduce the small

packet regression fixed by commit 63137bc5882a.

However, the optional ARP sender hardware address rewrite is different.

It writes through skbstorebits() at an offset relative to skb->data:

        skbstorebits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)

skbheaderpointer() only safely reads the ARP header; it does not make

the later sender hardware address range writable.  If that range is

still held in a nonlinear skb fragment backed by a splice-imported file

page, skbstorebits() maps the frag page and copies the new MAC address

directly into it.

Ensure the ARP SHA range is writable before reading the ARP header and

before calling skbstorebits().

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.8
-
3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093, https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49, https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b, https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b, https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d, https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0, https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87, https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53266.json, https://nvd.nist.gov/vuln/detail/CVE-2026-53266, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

8.8

CVSS Score
0
10

Basic Information

Base CVSS
8.8
EPSS Probability
0.00276%
EPSS Percentile
0.20224%
Introduced Version
63137bc5882a1882c553d389fdeeeace86ee1741,0,5.4.73,5.8.17,5.9.2,5.10.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0
Fix Available
67ba971ae02514d85818fe0c32549ab4bfa3bf49,5.5,5.9,5.10,5.10.259,5.15.210,6.1.176,6.6.143,6.12.94,6.18.36,7.0.13,0:4.18.0-553.143.1.el8_10,0:4.18.0-553.143.1.rt7.484.el8_10,0:5.14.0-687.23.1.el9_8,6.1.176-1,6.12.94-1,7.0.0-1012.12~24.04.1,7.0.0-1011.11~24.04.1,7.0.0-31.31~24.04.1,7.0.0-1018.18~24.04.1,6.8.0-1035.38,7.0.0-31.31.1~24.04.1,0:6.12.0-206.104.3.3.el9uek,0:5.15.0-323.211.3.3.el9uek,0:6.12.0-206.104.3.3.el10uek,0:5.15.0-323.211.3.3.el8uek,0:5.10.259-258.1043.amzn2,0:1.0-0.amzn2,0:5.15.210-148.245.amzn2,1:6.1.176-220.358.amzn2023,1:1.0-0.amzn2023,1:6.18.36-69.134.amzn2023,1:6.12.94-123.174.amzn2023,6.12.94-r0,6.18.36-r0,6.18.38-r0,6.18.48-r0,7.2.3-r0,6.18.44-r0,20260724-r0,20260911-r0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading