Junglewise Threat Intelligence

CVE-2026-31670: Linux Kernel memory exhaustion in rfkill subsystem

CVE-2026-31670 · Severity: medium · CVSS 5.5 · Published 2026-04-24

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's radio frequency (rfkill) subsystem allows a local user to trigger an unlimited number of system events without processing them. This can lead to the system running out of memory, potentially causing a complete system crash or denial of service. This affects various Linux-based systems, including specific industrial controllers from Siemens.

Technical details

The vulnerability exists in 'net/rfkill/core.c' where the kernel does not bound the number of 'rfkill_int_event' structures that can be queued for a single file descriptor. A local userspace process can open an rfkill file descriptor and trigger a large volume of events without reading them, leading to kernel memory exhaustion. The fix introduces a hard limit (MAX_RFKILL_EVENT = 1000) on the number of pending events per data source. Exploitation requires local access but no special privileges beyond the ability to interact with rfkill devices.

Affected products

  • Linux Linux Kernel All versions prior to fix (e.g., fixed in 6.1.x, 6.6.x, 7.x)
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-04-12: patched: Initial patch authored by Greg Kroah-Hartman
  • 2026-04-24: advisory: CVE published to NVD

References

Related threats