PatchSiren cyber security CVE debrief
CVE-2023-52838 Siemens CVE debrief
A resource leak vulnerability in the Linux kernel's imsttfb framebuffer driver probe function was resolved. The issue could lead to resource exhaustion during device initialization. Siemens has assessed this CVE as 'Misinformed' for affected industrial networking products, indicating the vulnerability does not apply to their specific product configurations. The advisory was initially published on August 12, 2025, and most recently updated on February 25, 2026, to reflect corrections to affected product listings and removal of rejected CVEs. No CVSS score has been assigned.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P or SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family and XCM-/XRM-/XCH-/XRH-300 family industrial Ethernet switches should verify their exposure status through the vendor advisory. While the underlying Linux kernel vulnerability exists, Siemens has assessed it as not applicable to their products. General Linux users with IMS Twin Turbo framebuffer hardware should ensure kernel updates are applied.
Technical summary
The vulnerability exists in the imsttfb (IMS Twin Turbo framebuffer) driver within the Linux kernel's fbdev subsystem. A resource leak in the driver's probe function could occur during device initialization, potentially leading to resource exhaustion. The issue was resolved in the Linux kernel. Siemens has evaluated this CVE against their RUGGEDCOM RST2428P and SCALANCE X-family industrial Ethernet switches and determined the vulnerability to be 'Misinformed'—indicating it does not apply to their product configurations or the affected code path is not present/exploitable in their implementations.
Defensive priority
low
Recommended defensive actions
- Verify current firmware version on affected Siemens RUGGEDCOM RST2428P and SCALANCE X-family devices
- Review Siemens ProductCERT SSA-613116 advisory for definitive product impact assessment
- Apply vendor-recommended updates when available per organizational patch management policy
- Monitor CISA ICS advisories for subsequent updates to ICSA-25-226-15
Evidence notes
CVE published 2025-08-12; modified 2026-02-25. Siemens ProductCERT SSA-613116 advisory cited as authoritative source. CISA CSAF advisory ICSA-25-226-15 republished with updates through February 25, 2026. Threat assessment category 'impact' marked as 'Misinformed' for product IDs CSAFPID-0001, CSAFPID-0003, CSAFPID-0004.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-52838 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-52838
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-52838 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52838
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.