THREAT OPS › CVEs › CVE-2026-53266
CVE-2026-53266 — Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Vulnerability details
- Affected productsKernel
- KEV remediation due2026-09-21
Related reporting
- [NVD] CVE-2026-53266 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks thnvd
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-53266 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerabilitycisa_kev