Write-what-where Condition Affecting torvalds/linux package, versions [5.4.73,5.10.259)[5.10-rc1,5.15.210)[6.0-rc1,6.1.176)[6.2-rc1,6.6.143)[6.7-rc1,6.12.94)[6.13-rc1,6.18.36)[7.0-rc1,7.0.13)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked
EPSS
0.65% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TORVALDSLINUX-20065891
  • published23 Sept 2026
  • disclosed25 Jun 2026
  • creditUnknown

Introduced: 25 Jun 2026

CVE-2026-53266  (opens in a new tab)
CWE-123  (opens in a new tab)

How to fix?

Upgrade torvalds/linux to version 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13 or higher.

Overview

Affected versions of this package are vulnerable to Write-what-where Condition in the ebtables SNAT target, whose optional ARP sender hardware address rewrite calls skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) after only skb_header_pointer(), which reads the ARP header safely but does not make the sender hardware address range writable. A local user can have the configured MAC address copied straight into a splice-imported file page by sending ARP traffic whose sender hardware address range is still held in a nonlinear fragment, since skb_store_bits() maps that fragment page and writes into it. This affects only the ARP rewrite path and not the Ethernet source rewrite, which stays behind skb_ensure_writable(skb, 0) deliberately, and it requires an ebtables SNAT rule with the optional ARP rewrite configured on the bridge plus a packet reaching the hook with that range in a fragment backed by a splice-imported page.

CVSS Base Scores

version 4.0
version 3.1