PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-52818 Siemens CVE debrief

A vulnerability in the Linux kernel's AMD GPU driver (drm/amd) for SMU7 could allow array-index-out-of-bounds access, potentially leading to undefined behavior or system instability. The issue was resolved with a kernel patch. Siemens has assessed this CVE as not affecting their RUGGEDCOM RST2428P and SCALANCE product families, marking it as 'Misinformed' in their security advisory.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations running Linux systems with AMD GPUs using the SMU7 driver should ensure kernel patches are applied. Users of Siemens RUGGEDCOM and SCALANCE industrial networking equipment can disregard this CVE per vendor assessment.

Technical summary

The vulnerability exists in the Linux kernel's Direct Rendering Manager (DRM) subsystem for AMD GPUs, specifically in the SMU7 (System Management Unit 7) driver code. An array-index-out-of-bounds condition was identified and resolved. The UBSAN (Undefined Behavior Sanitizer) detected this issue, indicating potential undefined behavior that could lead to memory corruption or system instability. Siemens has determined this CVE does not affect their industrial networking products (RUGGEDCOM RST2428P, SCALANCE families), classifying it as 'Misinformed' in their security advisory.

Defensive priority

low

Recommended defensive actions

  • Verify Linux kernel version on AMD GPU systems and apply vendor-provided kernel updates containing the drm/amd SMU7 fix
  • For Siemens RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices, no action required per vendor assessment
  • Review CISA ICS recommended practices for industrial control system security posture
  • Monitor vendor security advisories for any reassessment of impact

Evidence notes

CVE published 2025-08-12. Siemens ProductCERT advisory SSA-613116 (via CISA ICSA-25-226-15) lists this CVE as 'Misinformed' impact for affected product families, indicating the vulnerability does not actually affect these products. The underlying Linux kernel issue was resolved in drm/amd SMU7 driver.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-52818 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-52818

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-52818 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52818

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.