PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-53170 Linux CVE debrief

A use-after-free vulnerability exists in the Linux kernel's block subsystem. The issue arises from the improper handling of flush requests during the destruction of a block queue. Specifically, the `blk_mq_clear_flush_rq_mapping` function is not called during SCSI probe, leading to a potential use-after-free error when iterating over tags. This vulnerability can be triggered by a local attacker with low privileges, potentially resulting in a denial-of-service or privilege escalation.

Vendor
Linux
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems, especially those using SCSI disks, should assess exposure and verify if their systems are affected by this vulnerability. Operational impact may include denial-of-service or privilege escalation.

Why it matters

A use-after-free vulnerability in the Linux kernel's block subsystem can lead to denial-of-service or privilege escalation. Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems should assess exposure and verify if their systems are affected.

  • Denial-of-service due to use-after-free error
  • Potential privilege escalation
  • Verification of affected Linux kernel versions and SCSI disk usage
  • Remediation requires patching the Linux kernel

Technical summary

The Linux kernel's block subsystem is vulnerable to a use-after-free error. The `blk_mq_clear_flush_rq_mapping` function is not called during SCSI probe, leading to a potential use-after-free error when iterating over tags. This issue can be triggered by a local attacker with low privileges. A use-after-free vulnerability exists in the Linux kernel's block subsystem. The issue arises from the improper handling of flush requests during the destruction of a block queue. Specifically, the `blk_mq_clear_flush_rq_mapping` function is not called during SCSI probe, leading to a potential use-after-free error when iterating over tags. This vulnerability can be triggered by a local attacker with low privileges, and it

Defensive priority

High

Recommended defensive actions

  • Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
  • Only build and run applications from trusted sources.
  • Monitor for and apply patches from the Linux kernel and affected vendors.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was discovered by a syzkaller test for v6.6, which found a use-after-free error in the `blk_mq_find_and_get_req` function. The issue is caused by the `blk_mq_destroy_queue` function not clearing flush requests from `tags->rqs[]` when `QUEUE_FLAG_INIT_DONE` is cleared in `del_gendisk`.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-53170 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-53170

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-53170 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-53170

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2024-53170

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-209-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-019113.json

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-019113.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.