Linux Kernel Out-of-Bounds Write Vulnerability

cve CVE-2026-53266 3 sources, 3 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Linux Kernel Out-of-Bounds Write Vulnerability Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in … the claim
Severity
HIGH NVD
important Red Hat
CVSS they disagree
8.8 NVD
7.5 Red Hat
Exploited
yes CISA Known Exploited Vulnerabilities
Known ransomware campaign use
Unknown CISA Known Exploited Vulnerabilities
Due date
2026-09-21 CISA Known Exploited Vulnerabilities
Fixed in
5.5, 5.9, 5.10 NVD
Vendor
Linux CISA Known Exploited Vulnerabilities
Linux NVD
Product
Kernel CISA Known Exploited Vulnerabilities
Linux NVD
CWE
CWE-787 CISA Known Exploited Vulnerabilities
CWE-787 NVD
CWE-825 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild · CISA Known Exploited Vulnerabilities 2026-09-18
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVlocal Lnetwork N
Attack complexity AClow Lhigh H
Privileges required PRlow Llow L
User interaction UInone Nnone N
Scope Schanged Cunchanged U
Confidentiality Chigh Hhigh H
Integrity Ihigh Hhigh H
Availability Ahigh Hhigh H

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-06-01first spoke of it: kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewriteRed Hat
2026-06-25first spoke of it: Linux Kernel Out-of-Bounds Write VulnerabilityNVD
2026-09-18first spoke of it: Linux Kernel Out-of-Bounds Write VulnerabilityCISA Known Exploited Vulnerabilities
2026-09-21Due dateCISA Known Exploited Vulnerabilities

What it is to other things

affectslinux/linux_kernel
NVD
made_bylinux
NVD

In words only, so not counted until a person confirms one:

affectslinux/kernel
CISA Known Exploited Vulnerabilities says “Linux · Kernel”
affectslinux/linux
NVD says “Linux · Linux”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD8.8
receipt
Source
NVD
Its words
8.8
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat7.5
receipt
Source
Red Hat
Its words
7.5
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-53266",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:73732",
    "RHSA-2026:71233",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:71601",
    "RHSA-2026:70797",
    "RHSA-2026:71325",
    "RHSA-2026:71657",
    "RHSA-2026:36645",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606",
    "RHSA-2026:39082",
    "RHSA-2026:39083"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:6.12.0-211.59.1.el10_2",
    "kernel-0:4.18.0-477.169.1.el8_8",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:4.18.0-372.217.1.el8_6",
    "kernel-0:4.18.0-553.143.1.el8_10",
    "kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:5.14.0-687.23.1.el9_8",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2",
    "kernel-0:2.6.32-754.64.1.el6"
  ],
  "bugzilla": "2485368",
  "bugzilla_description": "kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-01T12:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-53266.json",
  "severity": "important"
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-53266",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:73732",
    "RHSA-2026:71233",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:71601",
    "RHSA-2026:70797",
    "RHSA-2026:71325",
    "RHSA-2026:71657",
    "RHSA-2026:36645",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606",
    "RHSA-2026:39082",
    "RHSA-2026:39083"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:6.12.0-211.59.1.el10_2",
    "kernel-0:4.18.0-477.169.1.el8_8",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:4.18.0-372.217.1.el8_6",
    "kernel-0:4.18.0-553.143.1.el8_10",
    "kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:5.14.0-687.23.1.el9_8",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2",
    "kernel-0:2.6.32-754.64.1.el6"
  ],
  "bugzilla": "2485368",
  "bugzilla_description": "kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-01T12:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-53266.json",
  "severity": "important"
}
—
CWE
cwe
different words
CISA Known Exploited VulnerabilitiesCWE-787
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-787
Read by
field:cwes
Said since
2026-10-06 12:19 UTC
Last answered
2026-10-06 16:31 UTC
2026-10-06 12:19 UTCCWE-787
2026-09-28 11:44 UTC—
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
CWE
cwe
different words
NVDCWE-787
receipt
Source
NVD
Its words
CWE-787
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-787
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-825
receipt
Source
Red Hat
Its words
CWE-825
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-53266",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:73732",
    "RHSA-2026:71233",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:71601",
    "RHSA-2026:70797",
    "RHSA-2026:71325",
    "RHSA-2026:71657",
    "RHSA-2026:36645",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606",
    "RHSA-2026:39082",
    "RHSA-2026:39083"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:6.12.0-211.59.1.el10_2",
    "kernel-0:4.18.0-477.169.1.el8_8",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:4.18.0-372.217.1.el8_6",
    "kernel-0:4.18.0-553.143.1.el8_10",
    "kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:5.14.0-687.23.1.el9_8",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2",
    "kernel-0:2.6.32-754.64.1.el6"
  ],
  "bugzilla": "2485368",
  "bugzilla_description": "kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-01T12:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-53266.json",
  "severity": "important"
}
—
CWES
cwes
CISA Known Exploited VulnerabilitiesCWE-787
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-787
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2026-09-21
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2026-09-21
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Exploitation
exploitation
NVDactive
Reliable evidence that it is exploited in the wild.
receipt
Source
NVD
Its words
active
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCactive
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Fixed in
fixed_in
NVD5.5, 5.9, 5.10
receipt
Source
NVD
Its words
5.5, 5.9, 5.10
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTC5.5, 5.9, 5.10
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiestrue
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Yes
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Packages
packages
Red Hatkernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:6.12.0-211.59.1.el10_2, kernel-0:4.18.0-477.169.1.el8_8, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:4.18.0-372.217.1.el8_6, kernel-0:4.18.0-553.143.1.el8_10, kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:5.14.0-687.23.1.el9_8, kernel-0:3.10.0-1160.164.1.el7, kernel-0:5.14.0-427.152.1.el9_4, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2, kernel-0:2.6.32-754.64.1.el6
receipt
Source
Red Hat
Its words
kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:6.12.0-211.59.1.el10_2, kernel-0:4.18.0-477.169.1.el8_8, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:4.18.0-372.217.1.el8_6, kernel-0:4.18.0-553.143.1.el8_10, kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:5.14.0-687.23.1.el9_8, kernel-0:3.10.0-1160.164.1.el7, kernel-0:5.14.0-427.152.1.el9_4, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2, kernel-0:2.6.32-754.64.1.el6
Read by
field:affected_packages[]
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCkernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:6.12.0-211.59.1.el10_2, kernel-0:4.18.0-477.169.1.el8_8, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:4.18.0-372.217.1.el8_6, kernel-0:4.18.0-553.143.1.el8_10, kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:5.14.0-687.23.1.el9_8, kernel-0:3.10.0-1160.164.1.el7, kernel-0:5.14.0-427.152.1.el9_4, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2, kernel-0:2.6.32-754.64.1.el6
2026-09-29 09:44 UTCkernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:6.12.0-211.59.1.el10_2, kernel-0:4.18.0-477.169.1.el8_8, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:4.18.0-372.217.1.el8_6, kernel-0:4.18.0-553.143.1.el8_10, kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:5.14.0-687.23.1.el9_8, kernel-0:3.10.0-1160.164.1.el7, kernel-0:5.14.0-427.152.1.el9_4, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2
What the source handed over
{
  "CVE": "CVE-2026-53266",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:73732",
    "RHSA-2026:71233",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:71601",
    "RHSA-2026:70797",
    "RHSA-2026:71325",
    "RHSA-2026:71657",
    "RHSA-2026:36645",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606",
    "RHSA-2026:39082",
    "RHSA-2026:39083"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:6.12.0-211.59.1.el10_2",
    "kernel-0:4.18.0-477.169.1.el8_8",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:4.18.0-372.217.1.el8_6",
    "kernel-0:4.18.0-553.143.1.el8_10",
    "kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:5.14.0-687.23.1.el9_8",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2",
    "kernel-0:2.6.32-754.64.1.el6"
  ],
  "bugzilla": "2485368",
  "bugzilla_description": "kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-01T12:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-53266.json",
  "severity": "important"
}
—
Product
product
different words
CISA Known Exploited VulnerabilitiesKernel
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Kernel
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Product
product
different words
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCHIGH
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
high
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-53266",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:73732",
    "RHSA-2026:71233",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:71601",
    "RHSA-2026:70797",
    "RHSA-2026:71325",
    "RHSA-2026:71657",
    "RHSA-2026:36645",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606",
    "RHSA-2026:39082",
    "RHSA-2026:39083"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:6.12.0-211.59.1.el10_2",
    "kernel-0:4.18.0-477.169.1.el8_8",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:4.18.0-372.217.1.el8_6",
    "kernel-0:4.18.0-553.143.1.el8_10",
    "kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:5.14.0-687.23.1.el9_8",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2",
    "kernel-0:2.6.32-754.64.1.el6"
  ],
  "bugzilla": "2485368",
  "bugzilla_description": "kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-01T12:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-53266.json",
  "severity": "important"
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
CISA Known Exploited VulnerabilitiesLinux
receipt
Source
CISA Known Exploited Vulnerabilities
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2026-53266",
  "cwes": "CWE-787",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability"
}
—
Vendor
vendor
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "76280b78cc9f23bdc6438e10ad6dff148ef8375b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b7e91939ba9be805a62a257fa4e227dffbb88fa0",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "153ea96c806aea395daba907a4f88480b6ad5093",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "b18675263db1147c8e1cab625400c13a0d87bd2d",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "lessThan": "67ba971ae02514d85818fe0c32549ab4bfa3bf49",
                "status": "affected",
                "version": "63137bc5882a1882c553d389fdeeeace86ee1741",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
                "versionType": "git"
              },
              {
                "status": "affected",
                "version": "b7d23c2c87584eb429f115c078ed511be8b18e29",
                "versionType": "git"
              },
              {
                "lessThan": "5.5",
                "status": "affected",
                "version": "5.4.73",
                "versionType": "semver"
              },
              {
                "lessThan": "5.9",
                "status": "affected",
                "version": "5.8.17",
                "versionType": "semver"
              },
              {
                "lessThan": "5.10",
                "status": "affected",
                "version": "5.9.2",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "net/bridge/netfilter/ebt_snat.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "5.10"
              },
              {
                "lessThan": "5.10",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.259",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.210",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.176",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.143",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.94",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.36",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.13",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Out-of-Bounds Write Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "886AB560-B760-44F0-AD89-3F275E4C0F58",
                "versionEndExcluding": "5.5",
                "versionStartIncluding": "5.4.73",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BEFC3ACE-365D-48E7-9C0A-019C74CC0725",
                "versionEndExcluding": "5.9",
                "versionStartIncluding": "5.8.17",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "992FFB71-217E-40A6-B8BD-5AA742898F28",
                "versionEndExcluding": "5.10.259",
                "versionStartIncluding": "5.9.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
                "versionEndExcluding": "5.15.210",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
                "versionEndExcluding": "6.1.176",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
                "versionEndExcluding": "6.6.143",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
                "versionEndExcluding": "6.12.94",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
                "versionEndExcluding": "6.18.36",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
                "versionEndExcluding": "7.0.13",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0).  This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload.  Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n        skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable.  If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits()."
      }
    ],
    "id": "CVE-2026-53266",
    "lastModified": "2026-09-19T04:17:53.580",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.0,
          "impactScore": 6.0,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-53266",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-25T09:16:44.643",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Linux Kernel Out-of-Bounds Write Vulnerability
zetlyn/cve-kev · 2026-09-18
cwe CWE-787 cwes CWE-787 due_date 2026-09-21 exploited yes forensic_triage true known_ransomware_campaign_use Unknown product Kernel vendor Linux
kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite
zetlyn/cve-redhat · 2026-06-01
cvss 7.5 cvss_vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H cwe CWE-825 packages kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:6.12.0-211.59.1.el10_2, kernel-0:4.18.0-477.169.1.el8_8, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:4.18.0-372.217.1.el8_6, kernel-0:4.18.0-553.143.1.el8_10, kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:5.14.0-687.23.1.el9_8, kernel-0:3.10.0-1160.164.1.el7, kernel-0:5.14.0-427.152.1.el9_4, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2, kernel-0:2.6.32-754.64.1.el6 severity important source
Linux Kernel Out-of-Bounds Write Vulnerability
zetlyn/cve-nvd · 2026-06-25
automatable no cvss 8.8 cvss_vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H cwe CWE-787 exploitation active fixed_in 5.5, 5.9, 5.10 product Linux severity HIGH status Analyzed technical_impact total vendor Linux source