Review reviewHigh

CVE-2026-23242

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_data() dereferences qp->rx_fpdu->more_ddp_segs without checking, which may lead to a NULL pointer deref. Only check more_ddp_segs when rx_fpdu is present. KASAN splat: [ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7] [ 101.385869] RIP: 0010:siw_tcp_rx_data+0x13ad/0x1e50

CVSS
7.5
EPSS
0.45%
36.9% percentile
CISA KEV
Not listed
Published
2026.03.18
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.45%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_data() dereferences qp->rx_fpdu->more_ddp_segs without checking, which may lead to a NULL pointer deref. Only check more_ddp_segs when rx_fpdu is present. KASAN splat: [ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7] [ 101.385869] RIP: 0010:siw_tcp_rx_data+0x13ad/0x1e50

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < ab61841633d10e56a58c1493a262f0d02dba2f5e, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 8564dcc12fbb372d984ab45768cae9335777b274, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < ab957056192d6bd068b3759cb2077d859cca01f0, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < ffba40b67663567481fa8a1ed5d2da36897c175d, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 87b7a036d2c73d5bb3ae2d47dee23de465db3355, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 714c99e1dc8f85f446e05be02ba83972e981a817, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < ce025f7f5d070596194315eb2e4e89d568b8a755, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 14ab3da122bd18920ad57428f6cf4fade8385142, >= 5.3, >= V3.1.6, >= V3.1.5, >= 5.3.1 < 5.10.252, >= 5.11 < 5.15.202, >= 5.16 < 6.1.165, >= 6.2 < 6.6.128, >= 6.7 < 6.12.75, >= 6.13 < 6.18.14, >= 6.19 < 6.19.4, 5.3
Fixed versions
5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.14, 6.19.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-476