← All Advisories

CVE-2026-52999

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-52999

Key Details

CVECVE-2026-52999
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_osf: fix out-of-bounds read on option matching

In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once

and passed by reference to nf_osf_match_one() for each fingerprint

checked. During TCP option parsing, nf_osf_match_one() advances the

shared ctx->optp pointer.

If a fingerprint perfectly matches, the function returns early without

restoring ctx->optp to its initial state. If the user has configured

NF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint.

However, because ctx->optp was not restored, the next call to

nf_osf_match_one() starts parsing from the end of the options buffer.

This causes subsequent matches to read garbage data and fail

immediately, making it impossible to log more than one match or logging

incorrect matches.

Instead of using a shared ctx->optp pointer, pass the context as a

constant pointer and use a local pointer (optp) for TCP option

traversal. This makes nf_osf_match_one() strictly stateless from the

caller's perspective, ensuring every fingerprint check starts at the

correct option offset. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-52999
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-52999