← All Advisories

CVE-2026-46323

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-46323

Key Details

CVECVE-2026-46323
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-416 (Use After Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: gro: don't merge zcopy skbs

skb_gro_receive() can currently copy frags between the source and GRO

skb, without checking the zerocopy status, and in particular the

SKBFL_MANAGED_FRAG_REFS flag.

When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference

on the pages in shinfo->frags. Appending those frags to another skb's

frags without fixing up the page refcount can lead to UAF.

When either the last skb in the GRO chain (the one we would append

frags to) or the source skb is zerocopy, don't merge the skbs. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-46323
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-46323