Junglewise Threat Intelligence

CVE-2024-24859: Linux Kernel race condition in Bluetooth sniff interval functions

CVE-2024-24859 · Severity: medium · CVSS 4.6 · Published 2024-02-05

Technologies: Siemens SIMATIC S7-1500 TM MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A synchronization issue exists in the Bluetooth component of the Linux kernel. This flaw could allow an attacker with high-level access to disrupt Bluetooth services, potentially causing a system crash or service outage. This affects various Linux-based systems, including industrial automation hardware like Siemens SIMATIC controllers.

Technical details

A race condition was identified in the net/bluetooth component of the Linux kernel, specifically within the sniff_min_interval_set() and sniff_max_interval_set() functions. The vulnerability stems from improper synchronization during concurrent execution when setting Bluetooth sniff intervals. An attacker with high privileges and adjacent network access could exploit this race condition to trigger a 'sniffing exception,' leading to a denial of service (DoS). The issue affects kernel versions up to 3.19.8 and the 6.x branch up to 6.7.2. Siemens has also confirmed impact on the GNU/Linux subsystem of SIMATIC S7-1500 TM MFP devices.

Affected products

  • Linux Linux Kernel up to 3.19.8, 6.0 to 6.7.2, 6.8-rc1
  • Siemens SIMATIC S7-1500 TM MFP All versions using affected GNU/Linux subsystem

Timeline

  • 2024-02-05: disclosed: Initial disclosure of CVE-2024-24859
  • 2024-04-09: advisory: Siemens published advisory SSA-265688 confirming impact on SIMATIC S7-1500 TM MFP

References

Related threats