PatchSiren cyber security CVE debrief
CVE-2024-42096 Linux CVE debrief
CVE-2024-42096 is a medium-severity vulnerability (CVSS 5.1) in the Linux kernel affecting Siemens SIMATIC S7-1500 TM MFP industrial control systems with GNU/Linux subsystem. The vulnerability, published April 9, 2024, involves unsafe stack manipulation in the x86 `profile_pc()` function that could lead to out-of-bounds read conditions. The issue was resolved in the upstream Linux kernel by eliminating stack-based games in the profiling code. Siemens has confirmed this affects their industrial automation platform but has not released a patch as of the last advisory update (June 10, 2025). The vulnerability requires local access with high privileges, limiting exploitability but presenting availability risks in operational technology environments.
- Vendor
- Linux
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-12-12
- Original CVE updated
- 2025-08-12
- Advisory published
- 2023-12-12
- Advisory updated
- 2025-08-12
Who should care
Industrial control system operators, OT security engineers, Siemens SIMATIC platform administrators, manufacturing security teams, and organizations running embedded Linux systems in operational technology environments should prioritize awareness of this vulnerability given the lack of available patches and the criticality of availability in industrial settings.
Technical summary
The vulnerability exists in the Linux kernel's x86 architecture-specific `profile_pc()` function, which is used for program counter sampling during profiling. The function previously performed unsafe stack manipulation ('stack games') that could result in out-of-bounds memory access. This represents a CWE-125 (Out-of-bounds Read) condition. The CVSS 3.1 vector (AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H) indicates local attack vector, low attack complexity, high privileges required, no user interaction, with impacts to confidentiality (low) and availability (high). On affected Siemens SIMATIC S7-1500 TM MFP systems, exploitation could cause denial of service conditions in the GNU/Linux subsystem. The upstream kernel fix eliminates the problematic stack operations.
Defensive priority
medium
Recommended defensive actions
- Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
- Implement application whitelisting - only build and run applications from trusted sources
- Monitor for Siemens security advisories for future patch availability
- Apply defense-in-depth strategies for industrial control systems per CISA guidance
- Segment OT networks to limit lateral movement from compromised endpoints
Evidence notes
The vulnerability description indicates a resolved Linux kernel issue in x86 architecture code. CVSS vector confirms local attack vector with high privileges required. Siemens advisory ICSA-24-102-01 explicitly lists this CVE with no fix available status. The GNU/Linux subsystem on SIMATIC S7-1500 TM MFP represents an embedded industrial platform where kernel-level vulnerabilities can impact operational availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-42096 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-42096
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-42096 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-42096
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.