PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35934 Siemens CVE debrief

CVE-2024-35934 is a LOW severity vulnerability (CVSS 3.1: 2.5) in the Linux kernel's Shared Memory Communications (SMC) subsystem, specifically in the `smc_pnet_create_pnetids_list()` function. The issue involves excessive rtnl (rtnetlink) lock pressure that could lead to localized denial of service conditions. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem component. No fix is currently available from the vendor. The attack requires local access with low privileges, high attack complexity, and results in low availability impact with no confidentiality or integrity effects.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
LOW 2.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Organizations operating Siemens SIMATIC S7-1500 TM MFP industrial control systems with the GNU/Linux subsystem enabled should assess their exposure. System administrators responsible for OT/ICS environments, particularly those in manufacturing, process control, and critical infrastructure sectors using affected Siemens products, should implement the recommended access controls. Security teams managing industrial control system networks should incorporate this into their vulnerability management programs given the no-fix availability status. Linux kernel maintainers and distributors should track upstream fixes for incorporation into long-term support kernels used in embedded industrial systems.

Technical summary

The vulnerability exists in the Linux kernel's net/smc subsystem, specifically in `smc_pnet_create_pnetids_list()`. This function is part of the SMC-PNET (Shared Memory Communications over Physical Networks) implementation, which allows SMC to operate over standard Ethernet networks rather than requiring specialized hardware. The issue involves improper handling of the rtnl (rtnetlink) lock, which is a critical synchronization primitive for network configuration operations in Linux. Excessive pressure on this lock can cause system-wide networking delays and potential denial of service conditions. The vulnerability requires local access to the system and is rated LOW severity due to the high complexity of exploitation and limited impact scope.

Defensive priority

LOW

Recommended defensive actions

  • Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only
  • Only build and run applications from trusted sources
  • Monitor for vendor security updates from Siemens for future patch availability
  • Apply defense-in-depth strategies for industrial control system environments per CISA guidance
  • Review and implement ICS-CERT recommended practices for securing industrial control systems

Evidence notes

The vulnerability description indicates this is a kernel-level networking issue in the SMC (Shared Memory Communications) subsystem, which is used for high-performance networking in IBM Z and LinuxONE environments. The specific function `smc_pnet_create_pnetids_list()` is responsible for creating network device lists for SMC-PNET (SMC over physical networks). The rtnl_lock contention issue could cause system responsiveness degradation under specific conditions. Siemens has confirmed this affects their SIMATIC S7-1500 TM MFP product's GNU/Linux subsystem, which incorporates the vulnerable kernel code. The CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L) confirms local attack vector with high complexity required for exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35934 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35934

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35934 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35934

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.