HIGHVulnerability
Verified
Global
CISA KEV: Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Analysis
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-18. Remediation due: 2026-09-21.