← All Advisories

CVE-2026-31700

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31700

Key Details

CVECVE-2026-31700
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()

In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points

directly into the mmap'd TX ring buffer shared with userspace. The

kernel validates the header via __packet_snd_vnet_parse() but then

re-reads all fields later in virtio_net_hdr_to_skb(). A concurrent

userspace thread can modify the vnet_hdr fields between validation

and use, bypassing all safety checks.

The non-TPACKET path (packet_snd()) already correctly copies vnet_hdr

to a stack-local variable. All other vnet_hdr consumers in the kernel

(tun.c, tap.c, virtio_net.c) also use stack copies. The TPACKET TX

path is the only caller of virtio_net_hdr_to_skb() that reads directly

from user-controlled shared memory.

Fix this by copying vnet_hdr from the mmap'd ring buffer to a

stack-local variable before validation and use, consistent with the

approach used in packet_snd() and all other callers. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31700
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31700