CVE-2026-53266: Linux Kernel
Linux Kernel 包含在 ebtables SNAT 目標中輸出漏洞,允許一個 ARP 傳送器重寫硬體地址直接寫入非線性 socket-buffer 片段,由分散式匯入的檔案頁面支援。受影響的產品(產品)可能是終身(EoL)和/或終身(EoS)。建議使用者停止使用和/或向支援的版本過渡。
CISA (English)
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
- 廠商
- Linux
- 產品
- Kernel
- 漏洞
- Linux Kernel Out-of-Bounds Write Vulnerability
- 加入日期
- 2026年9月18日
- CISA 修補期限(美國聯邦機關)
- 2026年9月21日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-787
參考資料
- NVD — CVE-2026-53266
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02