Executive brief
A vulnerability has been identified in the Linux kernel's IPv6 networking component, which is also used in certain Siemens industrial controllers. The flaw occurs when deleting network addresses, potentially allowing a local attacker to cause a system crash or execute unauthorized code. This could lead to a complete loss of availability for the affected device or unauthorized access to sensitive data.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's net/ipv6/addrconf.c within the inet6_addr_del() function. The root cause is a regression where ipv6_del_addr() was called for a managed temporary address (mngtmpaddr) before the kernel finished reading the address flags (ifp->flags). This race condition or improper sequencing allows the memory associated with the inet6_ifaddr structure to be freed and subsequently accessed. A local attacker with sufficient privileges to manage network interfaces (e.g., via ioctl) could exploit this to trigger a kernel panic or potentially achieve arbitrary code execution. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel Fixed in 6.1.x, 6.6.x, 6.12.x, 6.13.x
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2026-01-13: disclosed: Patch submitted by Google engineers
- 2026-01-25: advisory: CVE published
- 2026-07-14: advisory: Siemens product advisory updated
References
- https://git.kernel.org/stable/c/2684610a9c9c53f262fd864fa5c407e79f304804
- https://git.kernel.org/stable/c/6e89d60b4f03014f7d412ce64b17a840840d490e
- https://git.kernel.org/stable/c/8b6dcb565e419846bd521e31d5e1f98e4d0e1179
- https://git.kernel.org/stable/c/9356b69d03d0f50cce91cebdabd33dda023fbd64
- https://git.kernel.org/stable/c/ddf96c393a33aef4887e2e406c76c2f8cda1419c
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html