PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35855 Siemens CVE debrief

A use-after-free vulnerability exists in the Linux kernel's Mellanox Spectrum switch driver (mlxsw) ACL TCAM subsystem. The flaw occurs when the rule activity update delayed work traverses configured rules while the rehash delayed work concurrently modifies the same entry pointer, leading to a race condition. The vulnerability was resolved by performing the activity query under the vregion->lock mutex to prevent concurrent access.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
NONE 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens industrial network infrastructure including SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, and RUGGEDCOM RST2428P switches running SINEC OS versions prior to V3.1. Critical infrastructure operators and manufacturing environments using these devices for industrial network segmentation should prioritize patching.

Technical summary

The vulnerability exists in the mlxsw (Mellanox switch) driver's spectrum_acl_tcam module. Two delayed work items—rule activity update and rehash—can race when accessing ventry->entry. The activity update work reads the entry pointer while the rehash work may free and reallocate it, causing use-after-free. The fix adds proper locking (vregion->lock) around the activity query to serialize access. The crash manifests as a KASAN slab-use-after-free in mlxsw_sp_acl_tcam_flower_rule_activity_get during workqueue execution on affected kernels.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided firmware updates to V3.1 or later for affected Siemens SCALANCE and RUGGEDCOM products
  • Verify SINEC OS version on affected industrial network devices and upgrade if below V3.1
  • Monitor vendor security advisories for additional affected product families
  • Implement network segmentation for industrial control systems per CISA recommended practices
  • Review and apply defense-in-depth strategies for ICS environments

Evidence notes

The vulnerability is documented in CISA ICS advisory ICSA-25-226-15, which references Siemens ProductCERT advisory SSA-613116. The issue affects Siemens industrial networking products running SINEC OS that incorporate the vulnerable Linux kernel mlxsw driver. The KASAN slab-use-after-free report shows the crash occurring in mlxsw_sp_acl_tcam_flower_rule_activity_get during workqueue processing.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35855 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35855

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35855 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35855

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.