← All Advisories

CVE-2026-31507

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31507

Key Details

CVECVE-2026-31507
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-415 (Double Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer

smc_rx_splice() allocates one smc_spd_priv per pipe_buffer and stores

the pointer in pipe_buffer.private. The pipe_buf_operations for these

buffers used .get = generic_pipe_buf_get, which only increments the page

reference count when tee(2) duplicates a pipe buffer. The smc_spd_priv

pointer itself was not handled, so after tee() both the original and the

cloned pipe_buffer share the same smc_spd_priv *.

When both pipes are subsequently released, smc_rx_pipe_buf_release() is

called twice against the same object:

1st call: kfree(priv) sock_put(sk) smc_rx_update_cons() [correct]

2nd call: kfree(priv) sock_put(sk) smc_rx_update_cons() [UAF]

KASAN reports a slab-use-after-free in smc_rx_pipe_buf_release(), which

then escalates to a NULL-pointer dereference and kernel panic via

smc_rx_update_consumer() when it chases the freed priv->smc pointer:

BUG: KASAN: slab-use-after-free in smc_rx_pipe_buf_release+0x78/0x2a0

Read of size 8 at addr ffff888004a45740 by task smc_splice_tee_/74

Call Trace:

<TASK>

dump_stack_lvl+0x53/0x70

print_report+0xce/0x650

kasan_report+0xc6/0x100

smc_rx_pipe_buf_release+0x78/0x2a0

free_pipe_info+0xd4/0x130

pipe_release+0x142/0x160

__fput+0x1c6/0x490

__x64_sys_close+0x4f/0x90

do_syscall_64+0xa6/0x1a0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

</TASK>

BUG: kernel NULL pointer dereference, address: 0000000000000020

RIP: 0010:smc_rx_update_consumer+0x8d/0x350

Call Trace:

<TASK>

smc_rx_pipe_buf_release+0x121/0x2a0

free_pipe_info+0xd4/0x130

pipe_release+0x142/0x160

__fput+0x1c6/0x490

__x64_sys_close+0x4f/0x90

do_syscall_64+0xa6/0x1a0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

</TASK>

Kernel panic - not syncing: Fatal exception

Beyond the memory-safety problem, duplicating an SMC splice buffer is

semantically questionable: smc_rx_update_cons() would advance the

consumer cursor twice for the same data, corrupting receive-window

accounting. A refcount on smc_spd_priv could fix the double-free, but

the cursor-accounting issue would still need to be addressed separately.

The .get callback is invoked by both tee(2) and splice_pipe_to_pipe()

for partial transfers; both will now return -EFAULT. Users who need

to duplicate SMC socket data must use a copy-based read path. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31507
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31507