PatchSiren

siemens CVE debriefs · Page 60

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50205

A division-by-zero vulnerability exists in the Linux kernel's ALSA firewire-lib subsystem. The `step` variable in `apply_constraint_to_size()` is initialized to zero and may remain zero if not modified within a loop, leading to a potential division-by-zero condition. This flaw was introduced by commit 826b5de90c0b and affects the PCM rule constraints for period/buffer size handling. The vulnerability requ [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50153

A null pointer dereference vulnerability exists in the Linux kernel's SCSI target core subsystem. The flaw occurs in target_alloc_device() when memory allocation for device queues fails. At this point, the code attempts to free the device structure using dev->transport->free_device(), but dev->transport has not yet been initialized, resulting in a null pointer dereference. The vulnerability was resolved b [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-50151

A slab-out-of-bounds write vulnerability exists in the Linux kernel's SMB client (CIFS) when handling encrypted SMB2 IOCTL requests. The flaw occurs in smb2_set_next_command() during request buffer consolidation for encryption. SMB2_ioctl_init() allocates a 448-byte buffer for the SMB2_IOCTL request; when a user provides an input buffer exceeding 328 bytes, the subsequent buffer squashing operation writes [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-50150

A use-after-free vulnerability exists in the Linux kernel's USB Type-C alternate mode (altmode) driver. The altmode device release function references its parent device without holding a reference to it, creating a race condition where the parent device may be freed before the altmode release completes. This flaw was resolved by adding proper reference counting: obtaining a reference to the parent during [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50148

This CVE addresses a wild-memory-access vulnerability in the Linux kernel's Bluetooth BNEP (Bluetooth Network Encapsulation Protocol) subsystem. The issue stems from improper error handling in the bnep_init() function, which ignores the return value of bnep_sock_init(). When bnep_sock_init() fails and cleans up its resources, subsequent module removal triggers bnep_sock_cleanup() to access already-freed m [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50142

A validation bypass vulnerability in the Linux kernel's XFRM (IPsec) subsystem allows local attackers to create malformed Security Associations (SAs) that bypass prefix length checks. The flaw occurs when `usersa.sel.family` is set to `AF_UNSPEC`, causing `verify_newsa_info` to skip validation of `prefixlen_s` and `prefixlen_d`. However, `copy_from_user_state` later sets `x->sel.family` to `usersa.family` [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50134

A field-spanning write error in the Linux kernel's drm/vboxvideo driver, affecting the vbva_mouse_pointer_shape structure, has been resolved. The vulnerability stemmed from a fake variable-length array (VLA) at the end of the structure that triggered memcpy safety checks. The fix replaces this with a proper VLA declaration. Siemens has identified this as affecting the GNU/Linux subsystem of the SIMATIC S7 [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-50127

A use-after-free vulnerability in the Linux kernel's taprio traffic scheduler (net/sched) allows local attackers to corrupt memory and potentially escalate privileges. The flaw occurs in taprio_change() where the 'admin' pointer can become dangling due to race conditions between schedule switching/removal and pointer updates. The critical section protected by q->current_entry_lock is insufficient to preve [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50121

This CVE affects the GNU/Linux subsystem within Siemens SIMATIC S7-1500 TM MFP industrial control systems. The vulnerability resides in the Linux kernel's NFS server (nfsd) implementation, specifically in how `nfsd_shrinker_work` operates in synchronous mode during `nfs4_state_shutdown_net`. When an administrator executes `echo 0 > /proc/fs/nfsd/threads` to shut down NFS server threads, the `nfs4_state_de [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50058

CVE-2024-50058 is a NULL pointer dereference vulnerability in the Linux kernel's serial core subsystem. The issue exists in `uart_shutdown()` where a `uart_port_dtr_rts(uport, false)` call is made without verifying that `uport` is non-NULL, despite a preceding NULL check that acknowledges `uport` can be NULL. This vulnerability is triggered only when the HUPCL (hang up on close) flag is set, which limits [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-50010

A race condition in the Linux kernel's execve() path could trigger spurious kernel warnings (WARN_ON) when the noexec mount flag is toggled concurrently with program execution. The vulnerable code path contained a redundant path_noexec() check wrapped in WARN_ON that was originally intended for debugging but could fire falsely due to the non-atomic nature of the check versus the actual permission validati [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-46854

CVE-2024-46854 is a high-severity information disclosure vulnerability in the Linux kernel's DPAA (Data Path Acceleration Architecture) network driver. The flaw occurs when transmitting packets smaller than 60 bytes (ETH_ZLEN), where up to three bytes of memory immediately following the packet buffer may be leaked onto the network. This constitutes an out-of-bounds read (CWE-125) that could expose sensiti [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-45018

A missing initialization vulnerability in the Linux kernel's netfilter flowtable subsystem affects Siemens SIMATIC S7-1500 TM MFP industrial control systems. The flaw involves an uninitialized extack (extended ACK) structure in flow offload operations, which can lead to undefined behavior. With a CVSS 3.1 score of 5.5 (MEDIUM), this local vulnerability requires low privileges but no user interaction, pote [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-44948

A vulnerability in the Linux kernel's x86 Memory Type Range Register (MTRR) handling could cause a general protection fault (#GP) and trigger a WARN_ON() on CPUs that do not support fixed MTRR capability. The issue occurs in mtrr_save_state(), which accesses fixed MTRR MSRs without first checking the capability bit. While the #GP is handled gracefully and is harmless, it results in an unnecessary kernel w [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-43834

A vulnerability in the Linux kernel's XDP (eXpress Data Path) subsystem could cause system instability when network drivers using page pools are torn down. The issue stems from an invalid wait context when `page_pool_destroy()` is called under `rcu_read_lock()`, leading to a potential deadlock or warning condition. Siemens has confirmed this affects the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP in [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-43828

A vulnerability in the Linux kernel's ext4 filesystem could cause an infinite loop during fast_commit replay. The issue stems from an uninitialized extent_status structure in ext4_es_find_extent_range(), which may contain garbage values leading to integer overflow and unbounded looping. This affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The vulnera [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-42312

CVE-2024-42312 is a Linux kernel vulnerability affecting the sysctl subsystem, specifically in how inode ownership fields (i_uid/i_gid) are initialized in /proc/sys inodes. The issue stems from incomplete initialization of these fields when set_ownership() callbacks skip setting them, potentially leading to use of uninitialized values. The vulnerability was resolved by ensuring i_uid/i_gid are always init [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-42305

A vulnerability in the Linux kernel's ext4 filesystem implementation has been identified, affecting Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem. The issue involves insufficient validation of directory entry structures (specifically the dot and dotdot entries) before converting a directory to indexed format using htree (directory indexing). This validation [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-42302

A use-after-free vulnerability exists in the Linux kernel's PCI Downstream Port Containment (DPC) handler. The flaw occurs when a DPC event and hot-removal of the same PCI hierarchy portion execute concurrently. The dpc_handler() function polls the configuration space of the first child device on the secondary bus to await readiness, but pci_bridge_wait_for_secondary_bus() fails to hold a reference on tha [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-42292

CVE-2024-42292 is a medium-severity out-of-bounds (OOB) memory access vulnerability in the Linux kernel's kobject_uevent subsystem, specifically within the zap_modalias_env() function. The flaw stems from an incorrect size calculation when moving memory blocks during MODALIAS environment variable processing. If MODALIAS is not the last variable in the environment parameter, the miscalculation causes memor [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-42283

CVE-2024-42283 is a kernel memory information disclosure vulnerability in the Linux kernel's networking subsystem, specifically within the nexthop implementation. The issue stems from improper initialization of reserved fields in the `struct nexthop_grp` structure when dumping nexthop information via Netlink. The `nla_put_nh_group()` function fails to initialize two reserved fields (`resvd1` and `resvd2`) [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-42281

This CVE addresses a vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem. The issue occurs when downgrading the Generic Segmentation Offload (GSO) size, which can trigger a BUG_ON() assertion failure during subsequent skb (socket buffer) segmentation. The fix involves linearizing the skb when downgrading gso_size to prevent this crash condition. Siemens has identified this vulnerabi [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-42265

CVE-2024-42265 is a speculative execution vulnerability in the Linux kernel's file descriptor handling. The issue exists in the `do_dup2()` function where branch misprediction could cause an out-of-bounds array access during speculative execution. While callers verify that `fd` does not exceed `->max_fds`, CPU speculative execution on a mispredicted path could execute `tofree = fdt->fd[fd]` with an invali [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-40993

A vulnerability in the Linux kernel's netfilter ipset subsystem involves improper use of rcu_dereference_protected(), which can lead to memory corruption or use-after-free conditions. The issue stems from incorrect RCU (Read-Copy-Update) synchronization primitives in the ipset code path. This affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem for extende [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-38567

CVE-2024-38567 is a medium-severity vulnerability (CVSS 5.5) affecting the carl9170 Wi-Fi driver in the Linux kernel, specifically impacting Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The vulnerability stems from insufficient input validation when handling USB Request Block (URB) submissions, where improper endpoint type checking could trigger kernel warni [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-38565

CVE-2024-38565 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's ar5523 Wi-Fi driver, affecting the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial controllers. The flaw involves improper endpoint verification in the USB Wi-Fi driver, where an endpoint in use lacks the expected type, potentially leading to denial of service conditions. The vulnerability was discovered th [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-38560

A missing null-termination check in the Linux kernel's SCSI BFA (Brocade Fibre Channel HBA) driver can cause an out-of-bounds read when sscanf is used on a user-supplied buffer. The driver allocates a kernel buffer sized to match user-supplied nbytes, copies exactly nbytes from userspace, and then processes the buffer with sscanf without ensuring NUL termination. This can lead to reading beyond buffer bou [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-38547

A null-pointer dereference vulnerability exists in the Intel AtomISP (Image Signal Processor) media driver, specifically within the `load_video_binaries` function in `ssh_css`. This flaw can be triggered when processing video firmware binaries, leading to a kernel crash and denial of service. The vulnerability affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control systems. Wi [truncated]

MEDIUM Siemens CVE published 2024-04-09

CVE-2024-36939

A vulnerability in the Linux kernel's NFS (Network File System) implementation could allow a local attacker to trigger a denial of service condition. The issue stems from improper error handling in nfs_net_init(), where the return value of rpc_proc_register() was ignored. When rpc_proc_register() fails but nfs_net_init() succeeds, subsequent destruction of the network namespace causes nfs_net_exit() to ca [truncated]

HIGH Siemens CVE published 2024-04-09

CVE-2024-36899

A use-after-free vulnerability in the Linux kernel's GPIO character device subsystem affects Siemens SIMATIC S7-1500 TM MFP industrial controllers. The flaw occurs in the gpiolib cdev implementation when gpio_chrdev_release() frees the watched_lines bitmap while a concurrent line release operation holds the notifier chain's read-write semaphore, creating a race condition that can lead to memory corruption [truncated]