Executive brief
A vulnerability exists in the Linux kernel's networking subsystem that could allow a local user to crash the system or potentially access sensitive information. The issue occurs when the system processes specifically malformed IPv6 routing rules. This affects various Linux-based systems, including certain Siemens industrial controllers, potentially impacting operational availability.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel netfilter module (ip6t_rt). The function rt_mt6_check() fails to validate that the 'addrnr' field in the 'rtinfo' structure stays within the bounds of the 'addrs[]' array (defined by IP6T_RT_HOPS). A local attacker with permissions to modify netfilter rules can provide a malformed rule with an oversized addrnr. When the match logic in rt_mt6() subsequently processes this rule, it may perform an out-of-bounds access, leading to a kernel crash (DoS) or information disclosure. The fix involves adding a bounds check during rule installation to reject malformed rules.
Affected products
- Linux Linux Kernel 2.6.12-rc2 to 6.13.x
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-03-25: disclosed: Vulnerability reported by researchers
- 2026-03-26: patched: Initial patch committed to Linux kernel tree
- 2026-04-25: advisory: CVE published
References
- https://git.kernel.org/stable/c/13e3e30ed3b5b67cc1db2bd58a5d09b0f07debfa
- https://git.kernel.org/stable/c/29ea965a1353bc8303877422f79c8211e9ba9c55
- https://git.kernel.org/stable/c/9d3f027327c2fa265f7f85ead41294792c3296ed
- https://git.kernel.org/stable/c/a28ebf6f99de270d6338ccdc3b49f3e818f99b7b
- https://git.kernel.org/stable/c/af9b7e2b765966457f4ec23be5bd34a141f89574
- https://git.kernel.org/stable/c/c6a503a9f4debc654e3a6a7ca1f7fce6a9953c59
- https://git.kernel.org/stable/c/d8795fde1f78669a87c87ac29fceab2f104daa8c