← All Advisories

CVE-2026-43027

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-43027

Key Details

CVECVE-2026-43027
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-07-14
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-416 (Use After Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_helper: pass helper to expect cleanup

nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy()

to remove expectations belonging to the helper being unregistered.

However, it passes NULL instead of the helper pointer as the data

argument, so expect_iter_me() never matches any expectation and all

of them survive the cleanup.

After unregister returns, nfnl_cthelper_del() frees the helper

object immediately. Subsequent expectation dumps or packet-driven

init_conntrack() calls then dereference the freed exp->helper,

causing a use-after-free.

Pass the actual helper pointer so expectations referencing it are

properly destroyed before the helper object is freed.

BUG: KASAN: slab-use-after-free in string+0x38f/0x430

Read of size 1 at addr ffff888003b14d20 by task poc/103

Call Trace:

string+0x38f/0x430

vsnprintf+0x3cc/0x1170

seq_printf+0x17a/0x240

exp_seq_show+0x2e5/0x560

seq_read_iter+0x419/0x1280

proc_reg_read+0x1ac/0x270

vfs_read+0x179/0x930

ksys_read+0xef/0x1c0

Freed by task 103:

The buggy address is located 32 bytes inside of

freed 192-byte region [ffff888003b14d00, ffff888003b14dc0) (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-43027
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-43027