PatchSiren cyber security CVE debrief
CVE-2024-58063 Siemens CVE debrief
A memory leak and invalid access vulnerability exists in the rtlwifi Linux kernel Wi-Fi driver, affecting the probe error path. The flaw occurs when the driver fails to properly clean up allocated memory during device initialization failures, leading to resource exhaustion and potential system instability. This vulnerability is present in the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control systems. The issue was disclosed on April 9, 2024, with the advisory subsequently updated multiple times through September 2025 to include additional related CVEs. No patch is currently available from the vendor.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-14
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-14
Who should care
Industrial control system operators, OT security teams, and organizations deploying Siemens SIMATIC S7-1500 TM MFP with GNU/Linux subsystem functionality should prioritize this vulnerability. The affected systems are commonly used in manufacturing and critical infrastructure environments where availability is paramount. Security teams responsible for kernel-level vulnerability management in embedded Linux systems should also monitor this issue.
Technical summary
The rtlwifi driver in the Linux kernel contains a memory leak and invalid memory access vulnerability in its probe error handling path. When device initialization fails, the driver does not properly release allocated resources, leading to memory exhaustion. This affects the GNU/Linux subsystem on Siemens SIMATIC S7-1500 TM MFP programmable logic controllers. The vulnerability requires local access with low privileges to trigger, resulting in high availability impact through potential system instability or denial of service. No firmware update is currently available; mitigation relies on access controls and trusted application sourcing.
Defensive priority
medium
Recommended defensive actions
- Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
- Build and run applications exclusively from trusted sources
- Monitor for kernel memory exhaustion indicators on affected systems
- Apply vendor patches when released per Siemens security advisory SSA-265688
- Implement network segmentation for industrial control systems per CISA ICS recommended practices
Evidence notes
Vulnerability identified in rtlwifi kernel driver probe error path; affects Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. Advisory ICSA-24-102-01 has undergone ten revision updates, most recently in September 2025, indicating ongoing tracking of related kernel vulnerabilities. CVSS 3.1 vector confirms local attack vector with low attack complexity and high availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-58063 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-58063
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-58063 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-58063
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.