Junglewise Threat Intelligence

CVE-2026-23010: Linux Kernel use-after-free in IPv6 inet6_addr_del

CVE-2026-23010 · Severity: high · CVSS 7.8 · Published 2026-01-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability has been identified in the Linux kernel's IPv6 networking component, which is also used in certain Siemens industrial controllers. The flaw occurs when deleting network addresses, potentially allowing a local attacker to cause a system crash or execute unauthorized code. This could lead to a complete loss of availability for the affected device or unauthorized access to sensitive data.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's net/ipv6/addrconf.c within the inet6_addr_del() function. The root cause is a regression where ipv6_del_addr() was called for a managed temporary address (mngtmpaddr) before the kernel finished reading the address flags (ifp->flags). This race condition or improper sequencing allows the memory associated with the inet6_ifaddr structure to be freed and subsequently accessed. A local attacker with sufficient privileges to manage network interfaces (e.g., via ioctl) could exploit this to trigger a kernel panic or potentially achieve arbitrary code execution. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel Fixed in 6.1.x, 6.6.x, 6.12.x, 6.13.x
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2026-01-13: disclosed: Patch submitted by Google engineers
  • 2026-01-25: advisory: CVE published
  • 2026-07-14: advisory: Siemens product advisory updated

References

Related threats