Skip to finding
important · Privilege — Linux

Attackers are exploiting an ebtables flaw that writes chosen bytes into shared file-backed pages.

Affects

Linux kernel netfilter bridge ebtables SNAT handling on systems with the vulnerable code and applicable ARP rewrite rules.

Namespace-local CAP_NET_ADMIN and an ARP-rewriting ebtables SNAT rule are required; ebt_snat then writes an attacker-chosen MAC address into a shared backing page without first making the fragment writable.

Detail and 3 sources

A patch exists, but public evidence does not identify the corrupted target or whether exploitation ends in host root, container escape, persistence, or another result.

Chain to watch
Obtain namespace-local CAP_NET_ADMIN on a host using the affected ARP SNAT path.→↓Drive attacker-chosen bytes into a shared file-backed page.→↓Identify the corrupted target and resulting privilege.→↓The corrupted object and final post-corruption capability are not public.
Unverified chainObtain an incident artifact or authoritative technical report identifying the target and final privilege.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026