PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-26697 Siemens CVE debrief

A vulnerability in the Linux kernel's nilfs2 filesystem could cause data corruption during dsync block recovery when small block sizes are used. The issue has been resolved in the kernel. Siemens has assessed this CVE as 'Misinformed' for its affected industrial networking products, indicating the vulnerability does not apply to these systems as initially reported.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations running Linux systems with nilfs2 filesystem on small block size configurations; operators of Siemens industrial networking equipment previously listed as affected

Technical summary

CVE-2024-26697 is a vulnerability in the Linux kernel's nilfs2 (NILFS2 log-structured filesystem) that could result in data corruption during dsync block recovery when small block sizes are used. The vulnerability was resolved in the Linux kernel. Siemens ProductCERT has assessed this CVE as 'Misinformed' for its RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family products, indicating the vulnerability does not actually affect these systems as initially reported. The CISA advisory was republished on February 25, 2026 based on updated Siemens guidance.

Defensive priority

low

Recommended defensive actions

  • Verify nilfs2 filesystem is not in use on affected systems if running Linux kernel versions prior to the fix
  • Review Siemens ProductCERT advisory SSA-613116 for current product impact assessment
  • Apply kernel updates from Linux distribution vendor if nilfs2 filesystem is required
  • Monitor CISA ICS advisories for any future changes to impact assessment

Evidence notes

The CISA CSAF advisory ICSA-25-226-15, republished on 2026-02-25 based on Siemens ProductCERT SSA-613116, lists this CVE with threat category 'impact' and details 'Misinformed' for product IDs CSAFPID-0001, CSAFPID-0004, and CSAFPID-0003. The original Linux kernel fix addressed data corruption in nilfs2 dsync block recovery for small block sizes. Siemens revision history shows corrections to affected products list and removal of rejected CVEs in subsequent updates.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-26697 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-26697

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-26697 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26697

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.