← All Advisories

CVE-2026-64422

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-64422

Key Details

CVECVE-2026-64422
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsSiemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, and Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Classified asCWE-190 (Integer Overflow or Wraparound)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes

Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP

socket state. The sysctl is stored as an `int` but copied into the

`u32` `tp->reordering` field for new sockets, so negative writes wrap

to large values.

With `tcp_mtu_probing=2`, the wrapped value can overflow the

`tcp_mtu_probe()` size calculation and drive the MTU probing path into

an out-of-bounds read. Route `tcp_reordering` writes through

`proc_dointvec_minmax()` and require it to be at least 1. Also require

`tcp_max_reordering` to be at least 1 so the configured maximum cannot

become negative either.

When registering the table for a non-init network namespace, relocate

`extra2` pointers that refer into `init_net.ipv4` so the

`tcp_reordering` upper bound follows that namespace's

`tcp_max_reordering`.

Harden `tcp_mtu_probe()` itself by computing `size_needed` as `u64`.

This keeps the send queue and window checks from being bypassed through

signed integer overflow. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-64422
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-64422