Junglewise Threat Intelligence

CVE-2025-46836: net-tools stack buffer overflow in get_name function

CVE-2025-46836 · Severity: medium · CVSS 6.6 · Published 2025-05-14

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux Foundation, Siemens.

Executive brief

A vulnerability has been identified in net-tools, a standard set of Linux networking utilities like ifconfig. These tools are used to manage and display network interface information on Linux systems. An attacker with local access could exploit this flaw to cause a system crash or potentially execute unauthorized code, which could disrupt operations or compromise the integrity of the affected device. This issue also impacts certain Siemens industrial controllers and Ruggedcom networking devices that utilize these Linux utilities.

Technical details

A stack-based buffer overflow exists in the get_name() function within interface.c of the net-tools package (versions <= 2.10). The vulnerability is caused by improper validation of interface labels read from /proc/net/dev, where labels longer than 15 bytes are copied into a fixed 16-byte stack buffer (IFNAMSIZ) without bounds checking. An attacker with local access can trigger this by manipulating the /proc filesystem (e.g., via unprivileged user namespaces) to include a malformed interface name. Successful exploitation can lead to arbitrary code execution or a denial-of-service (crash), though it does not inherently provide privilege escalation. A fix is available in net-tools version 2.20 and has been backported to various Linux distributions.

Affected products

  • Linux Foundation net-tools <= 2.10
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP >= V3.1.5
  • Siemens Ruggedcom Rox < 2.17.1

Timeline

  • 2025-05-14: disclosed: Initial disclosure and GitHub advisory published
  • 2025-05-14: advisory
  • 2025-05-31: patched: Debian LTS update released
  • 2026-05-12: advisory: Siemens security advisory updated to include this CVE

References

Related threats