PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-58063 Siemens CVE debrief

A memory leak and invalid access vulnerability exists in the rtlwifi Linux kernel Wi-Fi driver, affecting the probe error path. The flaw occurs when the driver fails to properly clean up allocated memory during device initialization failures, leading to resource exhaustion and potential system instability. This vulnerability is present in the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control systems. The issue was disclosed on April 9, 2024, with the advisory subsequently updated multiple times through September 2025 to include additional related CVEs. No patch is currently available from the vendor.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Industrial control system operators, OT security teams, and organizations deploying Siemens SIMATIC S7-1500 TM MFP with GNU/Linux subsystem functionality should prioritize this vulnerability. The affected systems are commonly used in manufacturing and critical infrastructure environments where availability is paramount. Security teams responsible for kernel-level vulnerability management in embedded Linux systems should also monitor this issue.

Technical summary

The rtlwifi driver in the Linux kernel contains a memory leak and invalid memory access vulnerability in its probe error handling path. When device initialization fails, the driver does not properly release allocated resources, leading to memory exhaustion. This affects the GNU/Linux subsystem on Siemens SIMATIC S7-1500 TM MFP programmable logic controllers. The vulnerability requires local access with low privileges to trigger, resulting in high availability impact through potential system instability or denial of service. No firmware update is currently available; mitigation relies on access controls and trusted application sourcing.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
  • Build and run applications exclusively from trusted sources
  • Monitor for kernel memory exhaustion indicators on affected systems
  • Apply vendor patches when released per Siemens security advisory SSA-265688
  • Implement network segmentation for industrial control systems per CISA ICS recommended practices

Evidence notes

Vulnerability identified in rtlwifi kernel driver probe error path; affects Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. Advisory ICSA-24-102-01 has undergone ten revision updates, most recently in September 2025, indicating ongoing tracking of related kernel vulnerabilities. CVSS 3.1 vector confirms local attack vector with low attack complexity and high availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-58063 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-58063

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-58063 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-58063

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.