Junglewise Threat Intelligence

CVE-2026-43025: Linux Kernel Netfilter out-of-bounds read in ctnetlink

CVE-2026-43025 · Severity: high · CVSS 7.3 · Published 2026-05-01

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local attacker to read sensitive information from the system's memory. The issue exists in the Netfilter component, which manages network traffic filtering and connection tracking. An exploit could lead to a system crash or the exposure of internal kernel data, potentially compromising the security of the entire operating system.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's netfilter/ctnetlink component due to improper validation of user-supplied helper names in connection tracking expectations. When a userspace process provides a different helper than the existing master conntrack helper via CTA_EXPECT_CLASS, the kernel fails to properly bound the request, leading to a slab-out-of-bounds read in nf_ct_expect_related_report. A local attacker with low privileges can exploit this to read bytes of kernel memory beyond the expectation boundary or cause a kernel panic (DoS). The fix involves ignoring explicit helper suggestions from userspace and strictly using the existing master conntrack helper.

Affected products

  • Linux Linux Kernel All versions prior to fixed stable releases (e.g., 6.x)
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-05-01: advisory: Initial CVE publication
  • 2026-04-11: patched: Fix committed to Linux stable tree

References

Related threats