Review reviewHigh

CVE-2026-23319

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim The root cause of this bug is that when 'bpf_link_put' reduces the refcount of 'shim_link->link.link' to zero, the resource is considered released but may still be referenced via 'tr->progs_hlist' in 'cgroup_shim_find'. The actual cleanup of 'tr->progs_hlist' in 'bpf_shim_tramp_link_release' is deferred. During this window, another process can cause a use-after-free via 'bpf_trampoline_link_cgroup_shim'. Based on Martin KaFai Lau's suggestions, I have created a simple...

CVSS
7.8
EPSS
0.13%
2.64% percentile
CISA KEV
Not listed
Published
2026.03.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim The root cause of this bug is that when 'bpf_link_put' reduces the refcount of 'shim_link->link.link' to zero, the resource is considered released but may still be referenced via 'tr->progs_hlist' in 'cgroup_shim_find'. The actual cleanup of 'tr->progs_hlist' in 'bpf_shim_tramp_link_release' is deferred. During this window, another process can cause a use-after-free via 'bpf_trampoline_link_cgroup_shim'. Based on Martin KaFai Lau's suggestions, I have created a simple...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= 69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e < 529e685e522b9d7fb379dbe6929dcdf520e34c8c, >= 69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e < 9b02c5c4147f8af8ed783c8deb5df927a55c3951, >= 69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e < cfcfa0ca0212162aa472551266038e8fd6768cff, >= 69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e < 3eeddb80191f7626ec1ef742bfff51ec3b0fa5c2, >= 69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e < 4e8a0005d633a4adc98e3b65d5080f93b90d356b, >= 69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e < 56145d237385ca0e7ca9ff7b226aaf2eb8ef368b, >= 6.0, >= V3.1.6, >= V3.1.5, >= 6.0.1 < 6.1.167, >= 6.2 < 6.6.130, >= 6.7 < 6.12.77, >= 6.13 < 6.18.17, >= 6.19 < 6.19.7, 6.0, 7.0
Fixed versions
6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416