← All Advisories

CVE-2026-31452

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31452

Key Details

CVECVE-2026-31452
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ext4: convert inline data to extents when truncate exceeds inline size

Add a check in ext4_setattr() to convert files from inline data storage

to extent-based storage when truncate() grows the file size beyond the

inline capacity. This prevents the filesystem from entering an

inconsistent state where the inline data flag is set but the file size

exceeds what can be stored inline.

Without this fix, the following sequence causes a kernel BUG_ON():

1. Mount filesystem with inode that has inline flag set and small size

2. truncate(file, 50MB) - grows size but inline flag remains set

3. sendfile() attempts to write data

4. ext4_write_inline_data() hits BUG_ON(write_size > inline_capacity)

The crash occurs because ext4_write_inline_data() expects inline storage

to accommodate the write, but the actual inline capacity (~60 bytes for

i_block + ~96 bytes for xattrs) is far smaller than the file size and

write request.

The fix checks if the new size from setattr exceeds the inode's actual

inline capacity (EXT4_I(inode)->i_inline_size) and converts the file to

extent-based storage before proceeding with the size change.

This addresses the root cause by ensuring the inline data flag and file

size remain consistent during truncate operations. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31452
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31452