CVE-2026-53266: Linux Kernel
Linux カーネルは、ARP 送信者ハードウェアアドレスがスプライスインポートされたファイルページでバックアップされた非線形ソケットバッファのフラグメントに直接書き込むことを可能にする、ebtables SNAT ターゲットのアウトバウンド書き込み脆弱性が含まれています。インパクトのある製品(s)は、エンド・オブ・ライフ(EoL)および/またはエンド・オブ・サービス(EoS)である可能性があります。ユーザーは、サポートされたバージョンへの使用および/または移行を中止することを推奨します。
CISA (English)
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
- ベンダー
- Linux
- 製品
- Kernel
- 脆弱性
- Linux Kernel Out-of-Bounds Write Vulnerability
- 追加日
- 2026/09/18
- CISA対応期限(米国連邦機関向け)
- 2026/09/21
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-787
参考情報
- NVD — CVE-2026-53266
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02