← All Advisories

CVE-2026-31449

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31449

Key Details

CVECVE-2026-31449
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ext4: validate p_idx bounds in ext4_ext_correct_indexes

ext4_ext_correct_indexes() walks up the extent tree correcting

index entries when the first extent in a leaf is modified. Before

accessing path[k].p_idx->ei_block, there is no validation that

p_idx falls within the valid range of index entries for that

level.

If the on-disk extent header contains a corrupted or crafted

eh_entries value, p_idx can point past the end of the allocated

buffer, causing a slab-out-of-bounds read.

Fix this by validating path[k].p_idx against EXT_LAST_INDEX() at

both access sites: before the while loop and inside it. Return

-EFSCORRUPTED if the index pointer is out of range, consistent

with how other bounds violations are handled in the ext4 extent

tree code. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31449
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31449