Executive brief
A vulnerability in the Linux kernel's radio frequency (rfkill) subsystem allows a local user to trigger an unlimited number of system events without processing them. This can lead to the system running out of memory, potentially causing a complete system crash or denial of service. This affects various Linux-based systems, including specific industrial controllers from Siemens.
Technical details
The vulnerability exists in 'net/rfkill/core.c' where the kernel does not bound the number of 'rfkill_int_event' structures that can be queued for a single file descriptor. A local userspace process can open an rfkill file descriptor and trigger a large volume of events without reading them, leading to kernel memory exhaustion. The fix introduces a hard limit (MAX_RFKILL_EVENT = 1000) on the number of pending events per data source. Exploitation requires local access but no special privileges beyond the ability to interact with rfkill devices.
Affected products
- Linux Linux Kernel All versions prior to fix (e.g., fixed in 6.1.x, 6.6.x, 7.x)
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-04-12: patched: Initial patch authored by Greg Kroah-Hartman
- 2026-04-24: advisory: CVE published to NVD
References
- https://git.kernel.org/stable/c/4bcd1615a4e2a185ae9edd27b4143d7dfa7134f4
- https://git.kernel.org/stable/c/673d2a3eef6e0ee9736501a150c9e4024a4e60a6
- https://git.kernel.org/stable/c/80ce4cb026f0a4c4532b6cad827b44debda6256a
- https://git.kernel.org/stable/c/82843afc19012a29ba863961ef494165aa1a88f4
- https://git.kernel.org/stable/c/a8c26800e0220e1550af012f5a20e50f5c78864d
- https://git.kernel.org/stable/c/b1e0c8d3ab58a0161db487bf5fc47adfcaf5d5ca
- https://git.kernel.org/stable/c/e3842779547c83150569071d9980517cc9029fc0