PatchSiren cyber security CVE debrief
CVE-2024-35895 Linux CVE debrief
CVE-2024-35895 is a lock inversion deadlock vulnerability in the Linux kernel's BPF sockmap/sockhash subsystem, affecting Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The vulnerability exists because BPF tracing programs can be invoked from any interrupt context, but the locks taken during map_delete_elem operations in sockmap were not hardirq-safe. When a BPF tracing program attempts to delete elements from a sockmap/sockhash map with interrupts disabled, a deadlock can occur due to lock inversion between CPU contexts. The kernel fix detects when map_delete_elem is invoked from a hardirq-unsafe context (interrupts disabled) and returns an error instead of proceeding. Map updates are not affected as the BPF verifier already prevents updating sockmap/sockhash from BPF tracing programs.
- Vendor
- Linux
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-14
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-14
Who should care
Organizations running Siemens SIMATIC S7-1500 TM MFP with GNU/Linux subsystem, industrial control system operators using BPF-based monitoring, and security teams managing Linux kernel deployments with sockmap/sockhash BPF maps.
Technical summary
The vulnerability stems from a design assumption in sockmap that element deletion occurs only in task context with interrupts enabled or softirq context. BPF tracing programs violate this assumption by executing in arbitrary interrupt contexts. The fix adds a context check to prevent map_delete_elem operations when interrupts are disabled, returning -EINVAL. The affected locks include htab bucket locks and host locks that form the inversion pattern: CPU0 takes htab lock then host lock, while CPU1 (interrupt path) takes host lock then attempts htab lock.
Defensive priority
medium
Recommended defensive actions
- Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
- Only build and run applications from trusted sources
- Monitor for anomalous BPF program loading or sockmap operations
- Apply vendor security updates when available
- Review BPF program deployments for tracing programs that manipulate sockmap/sockhash maps
Evidence notes
Vulnerability disclosed in Linux kernel bpf/sockmap fix. Siemens CSAF advisory ICSA-24-102-01 confirms affected product. CVSS 5.5 (MEDIUM) per source. No known exploitation in the wild. No patch available per vendor remediation statement.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-35895 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-35895
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-35895 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35895
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2024-35895
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.