PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-46804 Linux CVE debrief

CVE-2024-46804 is a vulnerability in the Linux kernel's AMD display driver (drm/amd/display) related to an array index check for HDCP DDC access. The vulnerability description indicates a missing bounds check that could lead to improper memory access during HDCP (High-bandwidth Digital Content Protection) DDC (Display Data Channel) operations. The CVE was published on August 12, 2025, and last modified on February 25, 2026. According to the source advisory, this CVE is marked as 'Misinformed' in the threat assessment, indicating it may have been incorrectly attributed or does not actually affect the listed Siemens products. The advisory revision history shows this CVE was retained while other rejected CVEs were removed in the February 24, 2026 update. Siemens ProductCERT SSA-355557 is the authoritative source for affected product determination. No CVSS score or severity is available in the source data.

Vendor
Linux
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations running Siemens industrial networking products with embedded Linux systems using AMD graphics, particularly those implementing HDCP content protection. Security teams should verify actual affected status through Siemens ProductCERT rather than relying solely on initial CVE associations.

Technical summary

The vulnerability exists in the Linux kernel's Direct Rendering Manager (DRM) subsystem, specifically in the AMD display driver (drm/amd/display). The issue involves a missing array index check during HDCP DDC access operations. HDCP is used for protecting digital audio and video content, while DDC is the communication channel between a computer and display device. Without proper bounds checking, an out-of-bounds array access could occur during these operations. This is a third-party component vulnerability affecting the Linux kernel rather than Siemens proprietary software. The 'Misinformed' threat classification in the source advisory suggests the CVE may have been incorrectly associated with certain Siemens products or requires further validation.

Defensive priority

low

Recommended defensive actions

  • Verify with Siemens ProductCERT SSA-355557 for current affected product status
  • Review Linux kernel security updates for drm/amd/display fixes
  • Apply standard defense-in-depth practices for ICS networks per CISA guidance
  • Monitor CISA ICS advisories for updates to ICSA-25-226-07

Evidence notes

The source advisory ICSA-25-226-07 from CISA, based on Siemens ProductCERT SSA-355557, explicitly marks this CVE with threat category 'impact' and details 'Misinformed' for products CSAFPID-0006, CSAFPID-0002, and CSAFPID-0003. The revision history indicates this CVE was not among those removed as rejected in the February 24, 2026 update, suggesting it remains under evaluation. The vulnerability originates in the Linux kernel AMD display driver, not Siemens proprietary code.

Official resources

2025-08-12