← All Advisories

CVE-2026-31494

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31494

Key Details

CVECVE-2026-31494
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: macb: use the current queue number for stats

There's a potential mismatch between the memory reserved for statistics

and the amount of memory written.

gem_get_sset_count() correctly computes the number of stats based on the

active queues, whereas gem_get_ethtool_stats() indiscriminately copies

data using the maximum number of queues, and in the case the number of

active queues is less than MACB_MAX_QUEUES, this results in a OOB write

as observed in the KASAN splat.

==================================================================

BUG: KASAN: vmalloc-out-of-bounds in gem_get_ethtool_stats+0x54/0x78

[macb]

Write of size 760 at addr ffff80008080b000 by task ethtool/1027

CPU: [...]

Tainted: [E]=UNSIGNED_MODULE

Hardware name: raspberrypi rpi/rpi, BIOS 2025.10 10/01/2025

Call trace:

show_stack+0x20/0x38 (C)

dump_stack_lvl+0x80/0xf8

print_report+0x384/0x5e0

kasan_report+0xa0/0xf0

kasan_check_range+0xe8/0x190

__asan_memcpy+0x54/0x98

gem_get_ethtool_stats+0x54/0x78 [macb

926c13f3af83b0c6fe64badb21ec87d5e93fcf65]

dev_ethtool+0x1220/0x38c0

dev_ioctl+0x4ac/0xca8

sock_do_ioctl+0x170/0x1d8

sock_ioctl+0x484/0x5d8

__arm64_sys_ioctl+0x12c/0x1b8

invoke_syscall+0xd4/0x258

el0_svc_common.constprop.0+0xb4/0x240

do_el0_svc+0x48/0x68

el0_svc+0x40/0xf8

el0t_64_sync_handler+0xa0/0xe8

el0t_64_sync+0x1b0/0x1b8

The buggy address belongs to a 1-page vmalloc region starting at

0xffff80008080b000 allocated at dev_ethtool+0x11f0/0x38c0

The buggy address belongs to the physical page:

page: refcount:1 mapcount:0 mapping:0000000000000000

index:0xffff00000a333000 pfn:0xa333

flags: 0x7fffc000000000(node=0|zone=0|lastcpupid=0x1ffff)

raw: 007fffc000000000 0000000000000000 dead000000000122 0000000000000000

raw: ffff00000a333000 0000000000000000 00000001ffffffff 0000000000000000

page dumped because: kasan: bad access detected

Memory state around the buggy address:

ffff80008080b080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

ffff80008080b100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

>ffff80008080b180: 00 00 00 00 00 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8

^

ffff80008080b200: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8

ffff80008080b280: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8

==================================================================

Fix it by making sure the copied size only considers the active number of

queues. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31494
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31494