kevmap

Coverage › CVE-2026-53266

CVE-2026-53266 Unmapped

Linux Kernel Out-of-Bounds Write Vulnerability

Vendor / product
Linux — Kernel
Description (CISA)
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Added to KEV
2026-09-18 — after the latest CTID mapping snapshot (2025-07-28)
Due date
2026-09-21
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Known ransomware use
Unknown
Forensic triage (CISA)
Yes
CWE
CWE-787
CISA notes
This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see:
https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87
https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b
https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0
https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b
https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093
https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d
https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5
https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49
BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
https://nvd.nist.gov/vuln/detail/CVE-2026-53266
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2026-53266. This entry was added to KEV on 2026-09-18, after that snapshot; of the 325 entries added since, 0 have a mapping. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-787) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.