Junglewise Threat Intelligence

CVE-2026-31674: Linux Kernel out-of-bounds access in netfilter ip6t_rt

CVE-2026-31674 · Severity: high · CVSS 7.1 · Published 2026-04-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's networking subsystem that could allow a local user to crash the system or potentially access sensitive information. The issue occurs when the system processes specifically malformed IPv6 routing rules. This affects various Linux-based systems, including certain Siemens industrial controllers, potentially impacting operational availability.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel netfilter module (ip6t_rt). The function rt_mt6_check() fails to validate that the 'addrnr' field in the 'rtinfo' structure stays within the bounds of the 'addrs[]' array (defined by IP6T_RT_HOPS). A local attacker with permissions to modify netfilter rules can provide a malformed rule with an oversized addrnr. When the match logic in rt_mt6() subsequently processes this rule, it may perform an out-of-bounds access, leading to a kernel crash (DoS) or information disclosure. The fix involves adding a bounds check during rule installation to reject malformed rules.

Affected products

  • Linux Linux Kernel 2.6.12-rc2 to 6.13.x
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-03-25: disclosed: Vulnerability reported by researchers
  • 2026-03-26: patched: Initial patch committed to Linux kernel tree
  • 2026-04-25: advisory: CVE published

References

Related threats