In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }
Update Linux/Linux to 5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to * if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scannet/x25: Fix potential double free of skb affects Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic). Severity is critical. In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }
Update Linux/Linux to 5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to * if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scannet/x25: Fix potential double free of skb affects Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic). Severity is critical. In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3f5e3005984645bf5bd129c6b13149879580b1fb || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f782dd382203b2a8c4552a628431b7de65a19a7b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <524371398d8463ea7e101fce2cbf3915645d1730 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <fa1dbc93530b34fab0da9862426fe9c918c74dc0 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c87dd137c0dad07cc55f98181ff380b0c23d2878 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d10a26aa4d072320530e6968ef945c8c575edf61 | 5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9, 3f5e3005984645bf5bd129c6b13149879580b1fb, f782dd382203b2a8c4552a628431b7de65a19a7b, 143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1, 524371398d8463ea7e101fce2cbf3915645d1730, fa1dbc93530b34fab0da9862426fe9c918c74dc0, c87dd137c0dad07cc55f98181ff380b0c23d2878, d10a26aa4d072320530e6968ef945c8c575edf61 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3f5e3005984645bf5bd129c6b13149879580b1fb || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f782dd382203b2a8c4552a628431b7de65a19a7b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <524371398d8463ea7e101fce2cbf3915645d1730 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <fa1dbc93530b34fab0da9862426fe9c918c74dc0 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c87dd137c0dad07cc55f98181ff380b0c23d2878 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d10a26aa4d072320530e6968ef945c8c575edf61 | 5d0aa038a90b30c9bedde0c41c1fdcd98ecb16e9, 3f5e3005984645bf5bd129c6b13149879580b1fb, f782dd382203b2a8c4552a628431b7de65a19a7b, 143d4fa68ae9efb83b0c55b12cc7f0d03732a2b1, 524371398d8463ea7e101fce2cbf3915645d1730, fa1dbc93530b34fab0da9862426fe9c918c74dc0, c87dd137c0dad07cc55f98181ff380b0c23d2878, d10a26aa4d072320530e6968ef945c8c575edf61 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard