PatchSiren cyber security CVE debrief
CVE-2024-38627 Siemens CVE debrief
A double-free vulnerability exists in the Linux kernel's System Trace Module (STM) class subsystem. The flaw occurs in `stm_register_device()` where `put_device(&stm->dev)` triggers `stm_device_release()`, which already frees the `stm` structure. A subsequent `vfree(stm)` call results in a double-free condition. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. Siemens has addressed this issue in SINEC OS V3.1 and later versions. The vulnerability was initially published on August 12, 2025, with subsequent advisory updates through February 25, 2026, including corrections to affected product listings and removal of rejected CVEs.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- NONE
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking equipment including RUGGEDCOM RST2428P switches and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices. System administrators maintaining Linux systems with STM class subsystem enabled. Industrial control system operators following CISA guidance for critical infrastructure protection.
Technical summary
The vulnerability is a classic double-free bug in the Linux kernel's System Trace Module (STM) class implementation. In `stm_register_device()`, when device registration fails, `put_device(&stm->dev)` is called, which decrements the reference count and triggers `stm_device_release()`. This release callback performs `kfree(stm)`, freeing the memory. However, the error handling path then executes `vfree(stm)`, attempting to free the same memory again. This use-after-free scenario can lead to memory corruption, potential kernel crashes, or exploitable conditions depending on heap state. The fix removes the redundant `vfree(stm)` call, relying solely on the device release mechanism for cleanup.
Defensive priority
medium
Recommended defensive actions
- Update affected Siemens SINEC OS devices to version 3.1 or later
- Review and apply vendor security advisories for SCALANCE and RUGGEDCOM product families
- Implement network segmentation for industrial control systems per CISA recommended practices
- Monitor for kernel updates from Linux distribution maintainers for non-Siemens systems using STM class subsystem
Evidence notes
The vulnerability description is derived from the Linux kernel commit message resolving the double-free in stm_register_device(). Siemens ProductCERT advisory SSA-613116 and CISA advisory ICSA-25-226-15 confirm affected products and remediation. The CVSS vector AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N indicates network attack vector with high complexity, no confidentiality or integrity impact, and no availability impact, resulting in a NONE severity score.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-38627 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-38627
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-38627 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38627
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.