PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35895 Linux CVE debrief

CVE-2024-35895 is a lock inversion deadlock vulnerability in the Linux kernel's BPF sockmap/sockhash subsystem, affecting Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The vulnerability exists because BPF tracing programs can be invoked from any interrupt context, but the locks taken during map_delete_elem operations in sockmap were not hardirq-safe. When a BPF tracing program attempts to delete elements from a sockmap/sockhash map with interrupts disabled, a deadlock can occur due to lock inversion between CPU contexts. The kernel fix detects when map_delete_elem is invoked from a hardirq-unsafe context (interrupts disabled) and returns an error instead of proceeding. Map updates are not affected as the BPF verifier already prevents updating sockmap/sockhash from BPF tracing programs.

Vendor
Linux
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Organizations running Siemens SIMATIC S7-1500 TM MFP with GNU/Linux subsystem, industrial control system operators using BPF-based monitoring, and security teams managing Linux kernel deployments with sockmap/sockhash BPF maps.

Technical summary

The vulnerability stems from a design assumption in sockmap that element deletion occurs only in task context with interrupts enabled or softirq context. BPF tracing programs violate this assumption by executing in arbitrary interrupt contexts. The fix adds a context check to prevent map_delete_elem operations when interrupts are disabled, returning -EINVAL. The affected locks include htab bucket locks and host locks that form the inversion pattern: CPU0 takes htab lock then host lock, while CPU1 (interrupt path) takes host lock then attempts htab lock.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
  • Only build and run applications from trusted sources
  • Monitor for anomalous BPF program loading or sockmap operations
  • Apply vendor security updates when available
  • Review BPF program deployments for tracing programs that manipulate sockmap/sockhash maps

Evidence notes

Vulnerability disclosed in Linux kernel bpf/sockmap fix. Siemens CSAF advisory ICSA-24-102-01 confirms affected product. CVSS 5.5 (MEDIUM) per source. No known exploitation in the wild. No patch available per vendor remediation statement.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35895 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35895

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35895 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35895

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2024-35895

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.