Executive brief
A vulnerability in the Linux kernel's module loader can cause the entire system to crash (kernel panic) when attempting to load a specially crafted or corrupted kernel module. This issue occurs because the system fails to verify certain internal index values within the module file before using them. An attacker with local access or a system processing corrupted files could trigger a complete service outage.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel module loader's 'simplify_symbols()' function. The root cause is a lack of bounds checking on the 'st_shndx' member of the Elf_Sym structure before it is used as an index into the 'info->sechdrs' array. An attacker can provide a malicious ELF module with an invalid section index (such as SHN_XINDEX/0xffff), triggering a page fault and subsequent kernel panic. This vulnerability can be reached during the module loading process, typically requiring local privileges to load modules, though it may also be triggered by corrupted modules generated by buggy tooling. Patches have been released across multiple stable kernel branches to add the necessary bounds validation.
Affected products
- Linux Linux Kernel All versions prior to the April 2026 patches
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2025-12-30: disclosed: Initial patch submission by Ihor Solodrai
- 2026-04-02: patched: Commits merged into various Linux stable branches
- 2026-04-22: advisory: CVE published to NVD
References
- https://git.kernel.org/stable/c/082f15d2887329e0f43fd3727e69365f5bfe5d2c
- https://git.kernel.org/stable/c/4bbdb0e48176fd281c2b9a211b110db6fd94e175
- https://git.kernel.org/stable/c/5d16f519b6eb1d071807e57efe0df2baa8d32ad6
- https://git.kernel.org/stable/c/6ba6957c640f58dc8ef046981a045da43e47ea23
- https://git.kernel.org/stable/c/ec2b22a58073f80739013588af448ff6e2ab906f
- https://git.kernel.org/stable/c/ef75dc1401d8e797ee51559a0dd0336c225e1776
- https://git.kernel.org/stable/c/f9d69d5e7bde2295eb7488a56f094ac8f5383b92