Junglewise Threat Intelligence

CVE-2026-23359: Linux Kernel stack-out-of-bounds write in BPF devmap

CVE-2026-23359 · Severity: high · CVSS 7.8 · Published 2026-03-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's networking component that could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system handles a large number of virtual network interfaces (macvlans) while processing specific types of network traffic. This could lead to a service outage or compromise the integrity of the operating system in environments using advanced networking features like XDP.

Technical details

A stack-based out-of-bounds write exists in kernel/bpf/devmap.c within the get_upper_ifindexes() function. The vulnerability is caused by a lack of bounds checking when iterating over upper network devices and writing their indices into a stack-allocated array. While callers assume a maximum nesting depth (MAX_NEST_DEV), certain configurations like numerous macvlans can exceed this limit. An attacker can trigger this by creating more than 8 macvlans on a device with an XDP program using BPF_F_BROADCAST and sending a packet to trigger the redirect path. The fix introduces a maximum parameter to get_upper_ifindexes() to enforce bounds and returns -EOVERFLOW if exceeded.

Affected products

  • Linux Linux Kernel Fixed in versions 5000e40, 75d4747, 88df604, 8a95fb9, b7bf516, ca83156, d2c31d8
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-02-25: disclosed: Initial patch authored
  • 2026-03-25: advisory: NVD publication date
  • 2026-03-25: patched: Commits merged into stable trees

References

Related threats