PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-22365 Siemens CVE debrief

CVE-2024-22365 is a medium-severity denial-of-service issue in linux-pam affecting versions before 1.6.0. According to the NVD record, a local attacker with low privileges can trigger a blocked login process through mkfifo-related behavior because an openat call used for protect_dir lacks O_DIRECTORY. The practical impact is availability loss for authentication and login workflows, not data exposure or integrity compromise.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Administrators and security teams running linux-pam on Linux systems should care, especially where PAM is part of interactive login, privilege elevation, or remote access flows. Distribution maintainers and platform operators should also review whether their packaged linux-pam version is below 1.6.0 or whether the upstream patch has already been backported.

Technical summary

NVD lists linux-pam versions before 1.6.0 as vulnerable, with a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The record states that an attacker can cause a denial of service by blocking the login process via mkfifo-related behavior, because the openat call for protect_dir does not use O_DIRECTORY. The NVD record also maps the weakness to CWE-664 as a secondary classification, while the primary weakness is listed as CWE-noinfo.

Defensive priority

Medium

Recommended defensive actions

  • Confirm whether any deployed linux-pam packages are earlier than 1.6.0.
  • Upgrade to linux-pam 1.6.0 or later where possible.
  • If immediate upgrade is not feasible, apply the upstream patch or a vendor backport referenced in the advisory record.
  • Review systems where PAM-mediated logins are operationally critical, since the main impact is blocked authentication and login availability.
  • Validate that downstream distribution advisories or package changelogs reflect the fix before and after deployment.

Evidence notes

The supplied NVD record publishes CVE-2024-22365 on 2024-02-06 and last modified it on 2026-05-12. The record cites an oss-security mailing list post from 2024-01-18, an upstream linux-pam commit, and the v1.6.0 release tag as reference material. The affected version range in NVD ends before 1.6.0. NVD assigns CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and lists the primary weakness as CWE-noinfo with CWE-664 as secondary.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-22365 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-22365

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-22365 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-22365

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.