CVE-2026-53266CISA KEVEPSS p56.0%

CVE-2026-53266Linux Kernel Out-of-Bounds Write Vulnerability

Linux / Kernel

Description

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Scoring

CVSS 8.8 ()
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS0.83% probability of exploitation · percentile 56.0% · 2026-10-05T12:00:23Z
Last modified2026-09-19

CISA KEV entry

Added to KEV: 2026-09-18

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.