Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

OOB write in Linux kernel ebtables SNAT target. ARP address rewrite lands in a nonlinear socket buffer. CVSS 8.8, public exploits confirmed. CISA KEV Sept. 18.

cat cve-2026-53266.json
Vendor
Linux
Product
Kernel
CVSS
8.8
EPSS (exploit probability)
0.1%
Status
kev
CISA patch-by (BOD 22-01)
Published

Out-of-bounds write in the ebtables SNAT target in the Linux kernel. When processing ARP packets, a hardware address rewrite in the SNAT target can write an ARP sender hardware address directly into a nonlinear socket-buffer fragment backed by a splice-imported file page, outside the bounds of the original allocation.

Red Hat rated this “high risk” and confirmed public exploits are already in circulation. Documented outcomes include denial of service, unintended system behavior, and local privilege escalation. Particularly relevant on systems running ebtables for network bridging or container networking.

CISA added this to the Known Exploited Vulnerabilities catalog on September 18, 2026. Federal agencies have until September 21, 2026 to apply mitigations under BOD 26-04. See the NVD record and your distribution vendor’s advisories for patch details.

Full coverage: CISA Adds Three Exploited Linux Kernel Flaws to KEV.