PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-56589 Linux CVE debrief

A vulnerability in the Linux kernel's hisi_sas SCSI driver, where a missing cond_resched() call in no forced preemption model kernels could cause call traces when an expander is connected to 12 high-performance SAS SSDs. The CISA advisory marks this as 'Misinformed' impact for Siemens products, indicating the vulnerability does not actually affect the listed Siemens industrial networking products (RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family). The CVE was published on 2025-08-12 and last modified on 2026-02-25.

Vendor
Linux
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations running Linux systems with HiSilicon SAS controllers and no forced preemption kernel configurations with high-density SAS SSD deployments; Siemens industrial networking product users seeking clarification on advisory applicability

Technical summary

The vulnerability exists in the Linux kernel's hisi_sas SCSI driver, which lacks a cond_resched() call for no forced preemption model kernels. This can result in call traces when an expander is connected to 12 high-performance SAS SSDs. However, CISA's advisory marks this as 'Misinformed' impact for the Siemens products listed (RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family), indicating these products are not actually affected by this kernel-level issue. The advisory was last updated on 2026-02-25 based on Siemens ProductCERT guidance.

Defensive priority

low

Recommended defensive actions

  • Verify that systems do not use the hisi_sas SCSI driver with no forced preemption kernel configurations and high-density SAS SSD expander setups
  • Review vendor security advisories for affected Linux kernel versions if running systems with HiSilicon SAS controllers
  • Apply standard kernel update practices for Linux systems using affected hardware configurations
  • For Siemens industrial networking products listed in this advisory, no action is required as the vulnerability is marked with misinformed impact

Evidence notes

The CISA CSAF advisory ICSA-25-226-07 explicitly categorizes the impact as 'Misinformed' for all listed Siemens product IDs (CSAFPID-0006, CSAFPID-0002, CSAFPID-0003). The vulnerability description describes a Linux kernel driver issue (hisi_sas SCSI driver) that is not applicable to the Siemens industrial networking products listed. The advisory was republished on 2026-02-25 based on Siemens ProductCERT SSA-355557 advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-56589 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-56589

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-56589 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-56589

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.