Junglewise Threat Intelligence

CVE-2026-31649: Linux Kernel stmmac integer underflow in jumbo_frm

CVE-2026-31649 · Severity: critical · CVSS 9.8 · Published 2026-04-24

Technologies: Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability exists in the Linux kernel's stmmac network driver, which is commonly used in embedded systems and industrial controllers like Siemens SIMATIC S7-1500. An attacker could send specially crafted network packets to trigger a system crash or gain unauthorized access to sensitive information stored in the device's memory. This could lead to operational downtime or the theft of proprietary data in industrial environments.

Technical details

An integer underflow vulnerability exists in the jumbo_frm() function within the stmmac driver's chain-mode implementation. The root cause is an unconditional subtraction where the linear buffer length (nopaged_len) is subtracted from the maximum buffer size (bmax) without verifying that nopaged_len is larger. When a packet has a small linear portion but large page fragments, this results in a massive unsigned integer value for the remaining length. This causes a loop to execute excessively, mapping arbitrary kernel memory to the DMA engine via dma_map_single(). On systems without an IOMMU, this allows for kernel memory disclosure and potential hardware-driven memory corruption. The fix involves clamping the buffer length to the minimum of the linear portion and the maximum buffer size.

Affected products

  • Linux Linux Kernel Fixed in versions 10d12b92, 275bdf76, 2c91b399, 513e0673, 51f4e090, 6fca757c, a2b68a9a, b7b80121
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-03-31: other: Vulnerability fixed in kernel source by Tyllis Xu
  • 2026-04-24: disclosed: CVE published

References

Related threats