PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-26903 Linux CVE debrief

A null pointer dereference vulnerability exists in the Linux kernel's Bluetooth RFCOMM subsystem, specifically within the rfcomm_check_security function. This flaw can lead to a local denial-of-service condition when exploited by an authenticated attacker with low privileges. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem, where Bluetooth functionality may be exposed. The issue was disclosed on April 9, 2024, and remains unpatched as of the latest advisory update. Organizations should implement access controls and trusted application policies to mitigate risk.

Vendor
Linux
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Industrial control system operators, OT security teams, Siemens SIMATIC S7-1500 TM MFP administrators, manufacturing security engineers, and organizations with Bluetooth-enabled industrial endpoints.

Technical summary

The vulnerability resides in the rfcomm_check_security function within the Linux kernel's Bluetooth RFCOMM protocol implementation. A null pointer dereference occurs when processing security checks, leading to kernel panic and system crash. The attack requires local access and low privileges, with no user interaction needed. The CVSS 3.1 score of 5.5 reflects medium severity with high availability impact but no confidentiality or integrity effects. Siemens has confirmed no patch is currently available for the SIMATIC S7-1500 TM MFP GNU/Linux subsystem.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
  • Implement application whitelisting to ensure only trusted applications are built and executed
  • Monitor for anomalous Bluetooth RFCOMM activity on affected systems
  • Apply vendor patches when Siemens releases updated firmware
  • Review CISA ICS recommended practices for defense-in-depth strategies

Evidence notes

CVE description confirms null-pointer dereference in rfcomm_check_security. CISA ICS advisory ICSA-24-102-01 identifies affected Siemens product. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H confirms local attack vector with availability impact. Advisory remediation section states 'Currently no fix is available' as of last modification.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-26903 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-26903

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-26903 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26903

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.