PatchSiren cyber security CVE debrief
CVE-2024-43871 Siemens CVE debrief
A memory leak vulnerability exists in the Linux kernel's device resource management (devres) subsystem, specifically within the devm_free_percpu() API. The flaw occurs because devm_free_percpu() incorrectly uses devres_destroy() instead of devres_release() when freeing per-CPU memory allocated via devm_alloc_percpu(). This causes the memory to not be properly released, leading to resource exhaustion over time. The vulnerability has been resolved in the Linux kernel by correcting the API implementation. Siemens has assessed this CVE as 'Misinformed' for affected industrial control system products, indicating the vulnerability does not actually impact the listed products as initially reported.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Linux kernel maintainers and developers of kernel device drivers using per-CPU allocations; operators of industrial control systems using Siemens RUGGEDCOM and SCALANCE networking equipment; security teams responsible for OT/ICS infrastructure patch management; organizations running embedded Linux systems with long uptimes where memory leaks could cause availability issues
Technical summary
The vulnerability exists in the Linux kernel's device resource management (devres) subsystem. The devm_free_percpu() function, used by device drivers to free per-CPU memory allocated via devm_alloc_percpu(), incorrectly calls devres_destroy() rather than devres_release(). The devres_destroy() function removes the resource from the device's managed resource list without invoking the actual release callback, leaving the per-CPU memory allocated. In contrast, devres_release() properly executes the release callback to free the underlying memory. This implementation error causes a memory leak each time devm_free_percpu() is invoked, potentially leading to resource exhaustion and system instability over time. The fix replaces devres_destroy() with devres_release() to ensure proper memory deallocation.
Defensive priority
medium
Recommended defensive actions
- Verify Linux kernel version in use and apply vendor-provided patches if running affected kernel versions
- Review Siemens ProductCERT advisory SSA-355557 for definitive product impact assessment
- For Siemens RUGGEDCOM RST2428P and SCALANCE product families, confirm current firmware version against vendor security notifications
- Implement standard ICS security practices including network segmentation and access controls per CISA recommended practices
- Monitor for kernel memory exhaustion indicators in systems utilizing per-CPU allocations through devm_alloc_percpu()
- Contact Siemens ProductCERT for clarification if product-specific impact remains uncertain
Evidence notes
The CVE description states the vulnerability was resolved in the Linux kernel by replacing devres_destroy() with devres_release() in devm_free_percpu(). The CISA CSAF advisory ICSA-25-226-07 (published 2025-08-12, modified 2026-02-25) lists this CVE with threat category 'impact' marked as 'Misinformed' for product IDs CSAFPID-0006, CSAFPID-0002, and CSAFPID-0003. Siemens ProductCERT advisory SSA-355557 is the authoritative source for product impact assessment. The CVSS score of 5.5 (MEDIUM) reflects availability impact through resource exhaustion. No known exploitation in the wild or ransomware campaign use has been reported.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-43871 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-43871
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-43871 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-43871
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.