PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35789 Linux CVE debrief

A use-after-free vulnerability exists in the Linux kernel's mac80211 Wi-Fi subsystem when handling station VLAN changes. The issue occurs when moving a station out of a VLAN and subsequently deleting that VLAN—the fast_rx entry retains a pointer to the freed VLAN's network device, leading to potential memory corruption. This vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The flaw was resolved in the Linux kernel by immediately invoking ieee80211_check_fast_rx after VLAN changes to properly clear stale pointers.

Vendor
Linux
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-17
Original CVE updated
2026-08-04
Advisory published
2024-05-17
Advisory updated
2026-08-04

Who should care

Organizations operating Siemens SIMATIC S7-1500 TM MFP industrial control systems with enabled GNU/Linux subsystems, particularly those utilizing Wi-Fi connectivity with VLAN segmentation. OT security teams, industrial network administrators, and asset owners in manufacturing, process control, and critical infrastructure sectors should prioritize access controls and monitoring for this vulnerability.

Technical summary

The vulnerability resides in the mac80211 subsystem's fast path receive (fast_rx) optimization. When a station is moved out of a VLAN and that VLAN is subsequently deleted, the fast_rx structure retains a dangling pointer to the VLAN's net_device. Subsequent packet processing through the fast_rx path dereferences this freed pointer, causing use-after-free memory corruption. The fix ensures ieee80211_check_fast_rx is called immediately after VLAN changes to invalidate stale fast_rx entries.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
  • Build and run applications exclusively from trusted sources
  • Monitor for kernel updates from Siemens that may address this vulnerability
  • Apply defense-in-depth strategies for industrial control system environments
  • Review network segmentation to limit exposure of affected devices

Evidence notes

The vulnerability description is sourced from CISA ICS Advisory ICSA-24-102-01, which references Siemens Security Advisory SSA-265688. The issue was resolved in the Linux kernel by adding a check to clear fast_rx entries when VLAN changes occur for non-4addr stations. Siemens has confirmed this vulnerability affects the GNU/Linux subsystem of SIMATIC S7-1500 TM MFP devices.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35789 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35789

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35789 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35789

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.