← All Advisories

CVE-2026-31680

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31680

Key Details

CVECVE-2026-31680
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: ipv6: flowlabel: defer exclusive option free until RCU teardown

`ip6fl_seq_show()` walks the global flowlabel hash under the seq-file

RCU read-side lock and prints `fl->opt->opt_nflen` when an option block

is present.

Exclusive flowlabels currently free `fl->opt` as soon as `fl->users`

drops to zero in `fl_release()`. However, the surrounding

`struct ip6_flowlabel` remains visible in the global hash table until

later garbage collection removes it and `fl_free_rcu()` finally tears it

down.

A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that

early `kfree()` and dereference freed option state, triggering a crash

in `ip6fl_seq_show()`.

Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches

the lifetime already required for the enclosing flowlabel while readers

can still reach it under RCU. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31680
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31680