PatchSiren cyber security CVE debrief
CVE-2024-39503 Siemens CVE debrief
A use-after-free vulnerability exists in the Linux kernel's netfilter ipset subsystem, specifically within the list:set type. The race condition occurs between namespace cleanup operations and garbage collection (gc) during RCU cleanup. When namespace cleanup destroys list:set type sets while garbage collection is waiting to run, the gc process subsequently accesses data from the already-destroyed set, resulting in use-after-free memory corruption. This vulnerability affects Siemens industrial networking products that incorporate the vulnerable Linux kernel components. The issue was initially published on August 12, 2025, with subsequent advisory updates through February 25, 2026, including corrections to affected product listings and clarifications regarding specific product family configurations.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, or RUGGEDCOM RST2428P industrial networking equipment. System administrators responsible for Linux-based industrial control systems using netfilter ipset with list:set configurations. Security teams monitoring OT/ICS environments for kernel-level vulnerabilities.
Technical summary
The vulnerability exists in the Linux kernel's netfilter ipset implementation, specifically the list:set type. A race condition between namespace cleanup and garbage collection (gc) operations during RCU cleanup can cause the gc process to access freed memory. When namespace cleanup destroys list:set type sets, the pending gc operation may still reference data from the destroyed set, resulting in use-after-free. This is a memory safety issue in kernel networking code that could potentially lead to denial of service or other undefined behavior. The vulnerability affects Siemens industrial networking products that incorporate vulnerable Linux kernel versions.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates for affected Siemens SCALANCE and RUGGEDCOM products when available
- Monitor Siemens ProductCERT advisory SSA-355557 for updated patch availability
- Implement network segmentation to limit exposure of affected industrial control system devices
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Review and apply Linux kernel security updates for systems under organizational control that use netfilter ipset with list:set configurations
Evidence notes
Vulnerability description sourced from CISA CSAF advisory ICSA-25-226-07 and Siemens ProductCERT SSA-355557. The use-after-free condition is specifically tied to the list:set type implementation in netfilter ipset. Advisory revision history indicates initial publication on 2025-08-12, with multiple updates through 2026-02-25 correcting product impact assessments.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-39503 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-39503
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-39503 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-39503
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.