Review reviewHigh

CVE-2026-23271

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

CVSS
7.8
EPSS
0.10%
0.84% percentile
CISA KEV
Not listed
Published
2026.03.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.10%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= 592903cdcbf606a838056bae6d03fc557806c914 < 4df1a45819e50993cb351682a6ae8e7ed2d233a0, >= 592903cdcbf606a838056bae6d03fc557806c914 < 4f8d5812337871227bb2c98669a87c306a2f86ef, >= 592903cdcbf606a838056bae6d03fc557806c914 < 5c48fdc4b4623533d86e279f51531a7ba212eb87, >= 592903cdcbf606a838056bae6d03fc557806c914 < 3f89b61dd504c5b6711de9759e053b082f9abf12, >= 592903cdcbf606a838056bae6d03fc557806c914 < bb190628fe5f2a73ba762a9972ba16c5e895f73e, >= 592903cdcbf606a838056bae6d03fc557806c914 < c9bc1753b3cc41d0e01fbca7f035258b5f4db0ae, >= 2.6.31, >= V3.1.6, >= V3.1.5, >= 2.6.31 < 6.1.167, >= 6.2 < 6.6.130, >= 6.7 < 6.12.77, >= 6.13 < 6.18.17, >= 6.19 < 6.19.7, 7.0
Fixed versions
6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-362