Executive brief
A synchronization issue exists in the Bluetooth component of the Linux kernel. This flaw could allow an attacker with high-level access to disrupt Bluetooth services, potentially causing a system crash or service outage. This affects various Linux-based systems, including industrial automation hardware like Siemens SIMATIC controllers.
Technical details
A race condition was identified in the net/bluetooth component of the Linux kernel, specifically within the sniff_min_interval_set() and sniff_max_interval_set() functions. The vulnerability stems from improper synchronization during concurrent execution when setting Bluetooth sniff intervals. An attacker with high privileges and adjacent network access could exploit this race condition to trigger a 'sniffing exception,' leading to a denial of service (DoS). The issue affects kernel versions up to 3.19.8 and the 6.x branch up to 6.7.2. Siemens has also confirmed impact on the GNU/Linux subsystem of SIMATIC S7-1500 TM MFP devices.
Affected products
- Linux Linux Kernel up to 3.19.8, 6.0 to 6.7.2, 6.8-rc1
- Siemens SIMATIC S7-1500 TM MFP All versions using affected GNU/Linux subsystem
Timeline
- 2024-02-05: disclosed: Initial disclosure of CVE-2024-24859
- 2024-04-09: advisory: Siemens published advisory SSA-265688 confirming impact on SIMATIC S7-1500 TM MFP