Junglewise Threat Intelligence

CVE-2026-23087: Linux Kernel memory leak in Xen PV SCSI backend driver

CVE-2026-23087 · Severity: medium · CVSS 5.5 · Published 2026-02-04

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's Xen SCSI backend driver, which is also used in certain Siemens industrial controllers. This flaw occurs when the system fails to properly release memory during specific hardware removal or error handling processes. Over time, an attacker could exploit this to exhaust system memory, potentially leading to a system crash or service disruption.

Technical details

A memory leak vulnerability (CWE-401) exists in the Linux kernel's Xen PV SCSI backend driver (drivers/xen/xen-scsiback.c). The root cause is the failure to call kfree() on the 'vscsiblk_info' structure within the scsiback_remove() function and related error paths in scsiback_probe(). A local attacker could potentially trigger this leak repeatedly to cause memory exhaustion and a Denial of Service (DoS). The issue has been resolved in multiple stable kernel branches (including 4.19.y, 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.12.y) by ensuring the structure is properly freed during driver cleanup.

Affected products

  • Linux Linux Kernel 3.18 to 6.13.y
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.6
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-12-23: disclosed: Initial patch submission by Abdun Nihaal
  • 2026-01-30: patched: Patch committed to stable kernel trees
  • 2026-02-04: advisory: CVE published by NVD

References

Related threats