PatchSiren cyber security CVE debrief
CVE-2024-41055 Siemens CVE debrief
CVE-2024-41055 is publicly documented in Siemens/CISA advisory material as a Linux kernel NULL pointer dereference condition tied to pfn_section_valid(). The supplied advisory states that a prior READ_ONCE() change did not prevent dereferencing a cleared ms->usage pointer, and that no fix was available at publication time.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - BIOS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Siemens SIMATIC S7-1500 TM MFP - BIOS operators, OT/ICS security teams, and Linux platform maintainers responsible for embedded systems that incorporate the affected kernel code.
Technical summary
The advisory describes a NULL pointer dereference in mm: pfn_section_valid(). A prior fix for a race in memory_section->usage added READ_ONCE() around ms->usage, but the value can still be cleared by section_deactivate(), so it must be checked before dereference. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local, low-privilege access with high availability impact and no confidentiality or integrity impact.
Defensive priority
Medium. The impact is availability-focused, the attack vector is local, and the supplied advisory lists no fix; however, OT/ICS environments should treat it seriously because it affects a Siemens product advisory and only workaround guidance is provided.
Recommended defensive actions
- Review Siemens advisory SSA-503939 and CISA ICSA-25-072-03 for the current status of the issue and any later remediation updates.
- Apply the supplied workaround guidance: only build and run applications from trusted sources on affected systems.
- Inventory Siemens SIMATIC S7-1500 TM MFP - BIOS assets and confirm whether they are present in your environment.
- Use standard ICS defense-in-depth practices from CISA guidance, including segmentation, monitoring, and least-privilege access for affected hosts.
- Monitor Siemens release and advisory channels for a fix, since the supplied notice states that no fix was available at publication time.
Evidence notes
The corpus identifies the issue as published on 2025-03-11 and revised on 2025-09-09 through CISA CSAF ICSA-25-072-03. The advisory text says the READ_ONCE() change alone is insufficient because ms->usage may be cleared, and the remediation section lists 'Currently no fix is available' plus the workaround 'Only build and run applications from trusted sources.' The supplied metadata also shows no KEV listing.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-41055 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-41055
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-41055 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-41055
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-503939.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-503939.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.