Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-53266
Linux Linux — netfilter: bridge: make ebt_snat ARP rewrite writable
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N C H H H 8.8 .0083 55.9 YES
AFFECTED
Product Versions Fixed
Linux 63137bc5882a1882c553d389fdeeeace86ee1741 – —
Linux 5.10 – 5.10.259
TIMELINE
Jun 9 Reserved by Linux
Jun 25 Published (CNA: Linux)
Sep 18 ADDED TO KEV — CVE-2026-53266 (Linux). Remediation due September 21, 2026.
Sep 22 DUE DATE PASSED — CVE-2026-53266 (Linux). CISA remediation deadline was September 21, 2026; still in catalog.
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet
payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check
the payload, not the Ethernet header, and would reintroduce the small
packet regression fixed by commit 63137bc5882a.
However, the optional ARP sender hardware address rewrite is different.
It writes through skb_store_bits() at an offset relative to skb->data:
skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)
skb_header_pointer() only safely reads the ARP header; it does not make
the later sender hardware address range writable. If that range is
still held in a nonlinear skb fragment backed by a splice-imported file
page, skb_store_bits() maps the frag page and copies the new MAC address
directly into it.
Ensure the ARP SHA range is writable before reading the ARP header and
before calling skb_store_bits().
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| June 9, 2026 | Reserved | Reserved by Linux |
| June 25, 2026 | Published | Published (CNA: Linux) |
| September 18, 2026 | KEV ADDED | ADDED TO KEV — CVE-2026-53266 (Linux). Remediation due September 21, 2026. |
| September 22, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-53266 (Linux). CISA remediation deadline was September 21, 2026; still in catalog. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 63137bc5882a1882c553d389fdeeeace86ee1741 | — |
| Linux | Linux | — | 5.10 | 5.10.259 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-53266 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.