important · Privilege — Linux
Attackers are exploiting an ebtables flaw that writes chosen bytes into shared file-backed pages.
Affects
Linux kernel netfilter bridge ebtables SNAT handling on systems with the vulnerable code and applicable ARP rewrite rules.
Namespace-local CAP_NET_ADMIN and an ARP-rewriting ebtables SNAT rule are required; ebt_snat then writes an attacker-chosen MAC address into a shared backing page without first making the fragment writable.
Detail and 3 sources
A patch exists, but public evidence does not identify the corrupted target or whether exploitation ends in host root, container escape, persistence, or another result.
Chain to watch
Obtain namespace-local CAP_NET_ADMIN on a host using the affected ARP SNAT path.→↓Drive attacker-chosen bytes into a shared file-backed page.→↓Identify the corrupted target and resulting privilege.→↓The corrupted object and final post-corruption capability are not public.
Unverified chainObtain an incident artifact or authoritative technical report identifying the target and final privilege.