PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-49902 Siemens CVE debrief

CVE-2024-49902 describes a vulnerability in the jfs filesystem component related to the Qualcomm MSM GPU driver. The issue involves assigning msm_gpu->pdev earlier in the initialization process to prevent null pointer dereferences in msm_gpu_cleanup. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has identified this CVE as affecting their RUGGEDCOM RST2428P (6GK6242-6PA00) product, though the source advisory marks the impact assessment as 'Misinformed' for the affected product IDs. The CVE appears to originate from the Linux kernel's jfs filesystem and MSM GPU driver interaction, where improper initialization ordering could lead to null pointer dereference conditions during cleanup operations. No CVSS score or severity rating is currently available in the source data. Organizations should consult the Siemens ProductCERT advisory for specific patch availability and applicability to their deployed systems.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens RUGGEDCOM RST2428P (6GK6242-6PA00) industrial networking equipment, industrial control system operators using SINEC OS with third-party Linux kernel components, and security teams responsible for OT/ICS infrastructure patch management.

Technical summary

The vulnerability exists in the jfs filesystem component's interaction with the Qualcomm MSM GPU driver. The root cause is improper initialization ordering where msm_gpu->pdev is not assigned early enough in the initialization process, potentially leading to null pointer dereferences during msm_gpu_cleanup operations. The fix involves assigning msm_gpu->pdev earlier in the initialization sequence to ensure proper cleanup handling.

Defensive priority

medium

Recommended defensive actions

  • Review Siemens ProductCERT advisory SSA-355557 for detailed product impact assessment and patch availability
  • Verify kernel version and jfs/MSM GPU driver configuration on affected Siemens RUGGEDCOM RST2428P deployments
  • Apply vendor-provided firmware updates when available per Siemens guidance
  • Monitor CISA ICS advisories for additional guidance on industrial control system protections

Evidence notes

Source CISA CSAF advisory ICSA-25-226-07 indicates this CVE was included in Siemens Third-Party Components in SINEC OS advisory. The threat category is marked as 'Misinformed' for affected product IDs CSAFPID-0006, CSAFPID-0002, and CSAFPID-0003. The advisory underwent four revisions, with the most recent on 2026-02-25 clarifying affected configurations and removing rejected CVEs.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-49902 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-49902

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-49902 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-49902

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.