← All Advisories

CVE-2026-46300

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-46300

Key Details

CVECVE-2026-46300
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: preserve shared-frag marker during coalescing

skb_try_coalesce() can attach paged frags from @from to @to. If @from

has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same

externally-owned or page-cache-backed frags, but the shared-frag marker

is currently lost.

That breaks the invariant relied on by later in-place writers. In

particular, ESP input checks skb_has_shared_frag() before deciding

whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP

receive coalescing has moved shared frags into an unmarked skb, ESP can

see skb_has_shared_frag() as false and decrypt in place over page-cache

backed frags.

Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged

frags. The tailroom copy path does not need the marker because it copies

bytes into @to's linear data rather than transferring frag descriptors. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-46300
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-46300