Junglewise Threat Intelligence

CVE-2026-31680: Linux Kernel use-after-free in IPv6 flowlabel

CVE-2026-31680 · Severity: high · CVSS 7.8 · Published 2026-04-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system attempts to read network flow information while that information is simultaneously being deleted. This can lead to a system instability or a complete crash, potentially disrupting operations or services running on the affected machine.

Technical details

A use-after-free vulnerability exists in net/ipv6/ip6_flowlabel.c due to a race condition between flowlabel release and RCU-protected readers. The function fl_release() prematurely frees 'fl->opt' for exclusive flowlabels when the user count drops to zero, even though the parent 'struct ip6_flowlabel' remains visible in the global hash table until garbage collection. A concurrent reader of /proc/net/ip6_flowlabel (via ip6fl_seq_show) can dereference this freed memory, resulting in a kernel oops or crash. The fix defers the freeing of the option block until the final RCU teardown in fl_free_rcu(). This affects various Linux kernel versions and downstream products like Siemens SIMATIC S7-1500 CPUs.

Affected products

  • Linux Linux Kernel Fixed in 6.14, 6.13, 6.12, 6.11, 6.6, 6.1, 5.15, 5.10, 5.4, 4.19
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-04-25: disclosed
  • 2026-04-18: patched: Patched in various stable kernel branches

References

Related threats