← All Advisories

CVE-2026-43011

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-43011

Key Details

CVECVE-2026-43011
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-415 (Double Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net/x25: Fix potential double free of skb

When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at

line 48 and returns 1 (error).

This error propagates back through the call chain:

x25_queue_rx_frame returns 1

|

v

x25_state3_machine receives the return value 1 and takes the else

branch at line 278, setting queued=0 and returning 0

|

v

x25_process_rx_frame returns queued=0

|

v

x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb)

again

This would free the same skb twice. Looking at x25_backlog_rcv:

net/x25/x25_in.c:x25_backlog_rcv() {

...

queued = x25_process_rx_frame(sk, skb);

...

if (!queued)

kfree_skb(skb);

} (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-43011
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-43011