PatchSiren cyber security CVE debrief
CVE-2024-38662 Siemens CVE debrief
CVE-2024-38662 is a MEDIUM-severity Linux kernel BPF vulnerability affecting the SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The issue stems from insufficient access control in the BPF verifier: BPF programs attached to tracepoints could perform map_delete operations on sockmap/sockhash map types, triggering locking rule violations. The kernel maintainers determined this was an unsupported artificial use scenario and extended the existing verifier check to restrict delete operations to only those BPF program types already permitted to update these map types. This is a local denial-of-service condition requiring high privileges to exploit.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Industrial control system operators using Siemens SIMATIC S7-1500 TM MFP with the GNU/Linux subsystem enabled; Linux kernel security teams; BPF subsystem maintainers; organizations running containerized or sandboxed workloads with BPF capabilities on affected hardware.
Technical summary
The Linux kernel BPF subsystem's verifier did not properly restrict delete operations on sockmap and sockhash map types. While update operations were already restricted to specific BPF program types, delete operations were not similarly constrained. This allowed BPF programs attached to tracepoints—program types not intended to manipulate these maps—to perform map_delete operations, causing locking rule violations. The fix extends the existing BPF_PROG_TYPE check to cover both update and delete operations, ensuring only appropriately privileged BPF program types can modify sockmap/sockhash contents.
Defensive priority
medium
Recommended defensive actions
- Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
- Build and run applications only from trusted sources
- Monitor for anomalous BPF program loading on affected systems
- Apply vendor patches when available per Siemens security advisory SSA-265688
Evidence notes
The vulnerability description indicates this was discovered through syzkaller fuzzing reports showing BPF tracepoint programs could trigger locking violations via map_delete on sockmap/sockhash. The fix extends existing verifier program-type restrictions to cover delete operations. Siemens has confirmed this affects the GNU/Linux subsystem of SIMATIC S7-1500 TM MFP industrial controllers.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-38662 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-38662
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-38662 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38662
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.