Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6145 articles · 219931 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-53266PATCHED
linux · linux_kernel

netfilter: bridge: make ebt_snat ARP rewrite writable

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

Affected Products

VendorProductVersions
linuxlinux_kernel63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 63137bc5882a1882c553d389fdeeeace86ee1741, 2f3839075a5f8dcf116c1abe35b36b018ac62445, 51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b, b7d23c2c87584eb429f115c078ed511be8b18e29, 5.4.73, 5.8.17, 5.9.2, 5.10

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmqradar siemcert_advisory90%

References

  • https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87
  • https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b
  • https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0
  • https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b
  • https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093
  • https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d
  • https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
  • https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49

Related News (11 articles)

Tier D
SecurityWeek2h ago
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security6h ago
Warnung vor Angriffen auf Linux-Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR3d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR24d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories25d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR52d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR59d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026)
→ No new info (linked only)
Tier A
Microsoft MSRC85d ago
CVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writable
→ No new info (linked only)
Tier C
VulDB88d ago
CVE-2026-53266 | Linux Kernel up to 7.0.12 netfilter skb_mac_header data information disclosure
→ No new info (linked only)
Tier C
Linux Kernel CVEs88d ago
CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
bf84ad7c7a9ede46e31afaa41a1ba06a159e8c8776280b78cc9f23bdc6438e10ad6dff148ef8375bb7e91939ba9be805a62a257fa4e227dffbb88fa0afd64b59c3de9bbbdd3759e834fdc55cda716e0b153ea96c806aea395daba907a4f88480b6ad5093b18675263db1147c8e1cab625400c13a0d87bd2dc9b5ff59feffb92a147a84a5aa28acd2cb8ff4c567ba971ae02514d85818fe0c32549ab4bfa3bf495.55.95.1005.10.2595.15.2106.1.1766.6.1436.12.946.18.367.0.137.1
PublishedJun 25, 2026
Last enriched88d agov2
Trending Score77
Source articles11
Independent7
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-53362EXPKEV
ipv6: account for fraggap on the paged allocation path
Trending: 89
HIGHCVE-2026-53359EXP
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Trending: 60
HIGHCVE-2026-64600EXP
xfs: resample the data fork mapping after cycling ILOCK
Trending: 52
HIGHCVE-2026-53366EXP
ipv4: account for fraggap on the paged allocation path
Trending: 47
HIGHCVE-2026-68121
pppoe: reload header pointer after dev_hard_header()
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026
Updated: severity, affectedVersions
Jun 25, 2026
Patch Available
Sep 19, 2026

Version History

v2
Last enriched 88d ago
v2Tier C88d ago

Updated severity to CRITICAL, added affected version 7.0.12, and noted no exploit is available.

severityaffectedVersions
via VulDB
v188d ago

Initial creation