CVE-2026-53266

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
08/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: bridge: make ebt_snat ARP rewrite writable<br /> <br /> The ebtables SNAT target keeps the Ethernet source address rewrite<br /> behind skb_ensure_writable(skb, 0). This is intentional: at the bridge<br /> ebtables hooks the Ethernet header is addressed through<br /> skb_mac_header()/eth_hdr(), while skb-&gt;data points at the Ethernet<br /> payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check<br /> the payload, not the Ethernet header, and would reintroduce the small<br /> packet regression fixed by commit 63137bc5882a.<br /> <br /> However, the optional ARP sender hardware address rewrite is different.<br /> It writes through skb_store_bits() at an offset relative to skb-&gt;data:<br /> <br /> skb_store_bits(skb, sizeof(struct arphdr), info-&gt;mac, ETH_ALEN)<br /> <br /> skb_header_pointer() only safely reads the ARP header; it does not make<br /> the later sender hardware address range writable. If that range is<br /> still held in a nonlinear skb fragment backed by a splice-imported file<br /> page, skb_store_bits() maps the frag page and copies the new MAC address<br /> directly into it.<br /> <br /> Ensure the ARP SHA range is writable before reading the ARP header and<br /> before calling skb_store_bits().

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.73 (including) 5.5 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.8.17 (including) 5.9 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.9.2 (including) 5.10.259 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.210 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*