Executive brief
A vulnerability exists in the Linux kernel's BPF (Berkeley Packet Filter) subsystem, which is used for high-performance networking and security monitoring. A flaw in how the system manages memory for certain internal links could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue also affects certain Siemens industrial controllers that utilize the Linux kernel, potentially impacting the reliability of industrial operations.
Technical details
A use-after-free (UAF) vulnerability exists in 'bpf_trampoline_link_cgroup_shim' within the Linux kernel. The root cause is a race condition where 'bpf_link_put' reduces a reference count to zero, marking a resource as released, while it remains accessible via 'tr->progs_hlist' in 'cgroup_shim_find' before deferred cleanup occurs. A local attacker can exploit this timing window to trigger a UAF condition. The fix introduces an atomic non-zero check using 'bpf_link_inc_not_zero' to ensure the reference count is only incremented if the resource has not already been slated for release. Patches have been merged into multiple stable kernel branches.
Affected products
- Linux Linux Kernel Fixed in various stable branches including 6.x and 5.x via specific patches
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2026-03-03: other: Patch submitted by developer
- 2026-03-25: advisory: NVD publication date
- 2026-07-14: other: Siemens advisory updated with affected industrial products
References
- https://git.kernel.org/stable/c/3eeddb80191f7626ec1ef742bfff51ec3b0fa5c2
- https://git.kernel.org/stable/c/4e8a0005d633a4adc98e3b65d5080f93b90d356b
- https://git.kernel.org/stable/c/529e685e522b9d7fb379dbe6929dcdf520e34c8c
- https://git.kernel.org/stable/c/56145d237385ca0e7ca9ff7b226aaf2eb8ef368b
- https://git.kernel.org/stable/c/9b02c5c4147f8af8ed783c8deb5df927a55c3951
- https://git.kernel.org/stable/c/cfcfa0ca0212162aa472551266038e8fd6768cff
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html