PatchSiren cyber security CVE debrief
CVE-2024-26793 Siemens CVE debrief
This CVE addresses a use-after-free and null-pointer dereference vulnerability in the Linux kernel's GTP (GPRS Tunneling Protocol) driver, specifically within the gtp_newlink() function. The vulnerability was resolved in the Linux kernel, indicating a memory safety issue that could potentially lead to system instability or privilege escalation. The CISA CSAF advisory ICSA-25-226-15, published 2025-08-12 and last modified 2026-02-25, covers this CVE for Siemens industrial networking products. Notably, the advisory's threat assessment categorizes the impact as 'Misinformed' for the affected product IDs, suggesting potential clarification or correction of earlier impact assessments. Siemens ProductCERT advisory SSA-613116 provides the primary vendor guidance. The 2026-02-25 revision represents a CISA republication based on updated Siemens guidance, following earlier corrections to affected product listings in February 2026.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, or RUGGEDCOM RST2428P industrial networking equipment. Telecommunications providers and industrial operators using Linux-based systems with GTP tunneling capabilities. Security teams responsible for industrial control system infrastructure and kernel-level vulnerability management.
Technical summary
The vulnerability exists in the Linux kernel's GTP (GPRS Tunneling Protocol) implementation, specifically in the gtp_newlink() function used during network interface creation. The flaw involves both use-after-free and null-pointer dereference conditions, indicating improper memory management during object lifecycle handling. The GTP driver is used in telecommunications and industrial networking contexts for tunneling GPRS and UMTS traffic over IP networks. The kernel-level nature of this vulnerability means exploitation could affect system stability and potentially enable privilege escalation. Siemens has identified this as affecting certain SCALANCE and RUGGEDCOM industrial networking products that utilize the vulnerable kernel code. The 'Misinformed' threat categorization in the CSAF data suggests advisory updates have clarified the actual security impact versus initial assessments.
Defensive priority
medium
Recommended defensive actions
- Review Siemens ProductCERT advisory SSA-613116 for specific patch availability and version guidance for SCALANCE and RUGGEDCOM product families
- Verify kernel version on affected Siemens devices and apply vendor-provided updates when available
- Monitor CISA ICS advisories for additional guidance on industrial control system implementations
- Apply defense-in-depth strategies for industrial control systems per CISA recommended practices
Evidence notes
CVE description indicates kernel-level memory safety flaw in GTP networking subsystem. CISA CSAF advisory ICSA-25-226-15 published 2025-08-12, modified 2026-02-25. Threat category 'Misinformed' per CSAF threats field. Revision history shows product list corrections on 2026-02-12, CVE removal on 2026-02-24, and republication on 2026-02-25.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-26793 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-26793
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-26793 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26793
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.