Review reviewHigh

CVE-2025-68782

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd->t_task_cdb fails, it remains NULL but is later dereferenced in the 'err' path. In case of error, reset NULL t_task_cdb value to point at the default fixed-size buffer. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS
7.5
EPSS
0.50%
40.2% percentile
CISA KEV
Not listed
Published
2026.01.14
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.50%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd->t_task_cdb fails, it remains NULL but is later dereferenced in the 'err' path. In case of error, reset NULL t_task_cdb value to point at the default fixed-size buffer. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 6cac97b12bdab04832e0416d049efcd0d48d303b, >= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 45fd86b444105c8bd07a763f58635c87e5dc7aea, >= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 8727663ded659aad55eef21e3864ebf5a4796a96, >= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 0260ad551b0815eb788d47f32899fbcd65d6f128, >= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 0d36db68fdb8a3325386fd9523b67735f944e1f3, >= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 8edbb9e371af186b4cf40819dab65fafe109df4d, >= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 5053eab38a4c4543522d0c320c639c56a8b59908, >= 5.8, >= V3.1.6
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
Not available
CVE-2025-68782 — Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | SECUFOCUS NOW