Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local attacker to read sensitive information from the system's memory. The issue exists in the Netfilter component, which manages network traffic filtering and connection tracking. An exploit could lead to a system crash or the exposure of internal kernel data, potentially compromising the security of the entire operating system.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's netfilter/ctnetlink component due to improper validation of user-supplied helper names in connection tracking expectations. When a userspace process provides a different helper than the existing master conntrack helper via CTA_EXPECT_CLASS, the kernel fails to properly bound the request, leading to a slab-out-of-bounds read in nf_ct_expect_related_report. A local attacker with low privileges can exploit this to read bytes of kernel memory beyond the expectation boundary or cause a kernel panic (DoS). The fix involves ignoring explicit helper suggestions from userspace and strictly using the existing master conntrack helper.
Affected products
- Linux Linux Kernel All versions prior to fixed stable releases (e.g., 6.x)
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-05-01: advisory: Initial CVE publication
- 2026-04-11: patched: Fix committed to Linux stable tree
References
- https://git.kernel.org/stable/c/0f6c33697ccfac6499d0b7a4dbdec5d3a3a566cd
- https://git.kernel.org/stable/c/187b6ec5229ea93cb04c4f6d3b52efc80f513d0d
- https://git.kernel.org/stable/c/21a04c31db4057deec85fcd6cc63d720b38819c3
- https://git.kernel.org/stable/c/2ea0f35f235f70c133ad61fe05ba013753b978c6
- https://git.kernel.org/stable/c/917b61fa2042f11e2af4c428e43f08199586633a
- https://git.kernel.org/stable/c/e135f8e8212cbed12a03ab8dec77fa1247139897
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html