Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade torvalds/linux to version 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13 or higher.
Affected versions of this package are vulnerable to Write-what-where Condition in the ebtables SNAT target, whose optional ARP sender hardware address rewrite calls skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) after only skb_header_pointer(), which reads the ARP header safely but does not make the sender hardware address range writable. A local user can have the configured MAC address copied straight into a splice-imported file page by sending ARP traffic whose sender hardware address range is still held in a nonlinear fragment, since skb_store_bits() maps that fragment page and writes into it. This affects only the ARP rewrite path and not the Ethernet source rewrite, which stays behind skb_ensure_writable(skb, 0) deliberately, and it requires an ebtables SNAT rule with the optional ARP rewrite configured on the bridge plus a packet reaching the hook with that range in a fragment backed by a splice-imported page.