PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-42302 Siemens CVE debrief

A use-after-free vulnerability exists in the Linux kernel's PCI Downstream Port Containment (DPC) handler. The flaw occurs when a DPC event and hot-removal of the same PCI hierarchy portion execute concurrently. The dpc_handler() function polls the configuration space of the first child device on the secondary bus to await readiness, but pci_bridge_wait_for_secondary_bus() fails to hold a reference on that child device. If the child device is concurrently removed, subsequent accesses to its struct pci_dev cause a kernel oops. This vulnerability was introduced in kernel v6.3 when DPC event handling began calling pci_bridge_wait_for_secondary_bus(), and was backported to v5.10+ stable kernels. The issue affects Siemens SIMATIC S7-1500 TM MFP industrial control systems running the GNU/Linux subsystem.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Industrial control system operators using Siemens SIMATIC S7-1500 TM MFP with GNU/Linux subsystem, Linux kernel maintainers for v5.10+ stable branches, and organizations running PCI Express hot-plug capable systems with DPC enabled.

Technical summary

The vulnerability stems from a missing reference count in pci_bridge_wait_for_secondary_bus() when called from dpc_handler(). The function polls PCI configuration space of the first child device on a secondary bus without holding a reference, creating a race condition with concurrent hot-removal. When the child device is freed during hot-removal while dpc_handler() still attempts to access its struct pci_dev, a use-after-free occurs resulting in a kernel page fault. The fix requires acquiring a reference to the child device before polling and releasing it afterward. Affected code path: dpc_handler() → dpc_reset_link() → pci_bridge_wait_for_secondary_bus() → pci_dev_wait() → pci_bus_read_config_dword().

Defensive priority

HIGH

Recommended defensive actions

  • Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only
  • Only build and run applications from trusted sources
  • Monitor for kernel oops messages related to pci_bus_read_config_dword or dpc_handler indicating potential exploitation attempts
  • Apply vendor patches when available for the SIMATIC S7-1500 TM MFP GNU/Linux subsystem

Evidence notes

The vulnerability was resolved in the Linux kernel with a fix to acquire the missing reference on the child device in pci_bridge_wait_for_secondary_bus(). The issue was reported by Keith and affects kernels from v5.10+ due to backporting of commit 53b54ad074de. Siemens has confirmed this affects the SIMATIC S7-1500 TM MFP GNU/Linux subsystem with no patch currently available.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-42302 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-42302

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-42302 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-42302

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.