PatchSiren cyber security CVE debrief
CVE-2024-50039 Siemens CVE debrief
A vulnerability in the Linux kernel's network scheduler (net/sched) allows local attackers to cause a denial of service (system crash) by exploiting improper handling of the TCA_STAB parameter on non-root queueing disciplines (qdiscs). The issue stems from an assumption that packet length remains invariant between enqueue() and dequeue() handlers, which fails when TCA_STAB is applied to child qdiscs rather than only the root qdisc. A syzbot-reproducible crash scenario involves combining Token Bucket Filter (TBF) with Stochastic Fairness Queueing (SFQ) and applying STAB to SFQ. Siemens has identified affected products in its industrial networking portfolio, including RUGGEDCOM RST2428P and SCALANCE switch families running SINEC OS. The vulnerability was resolved by restricting TCA_STAB acceptance to root qdisc only.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking equipment (RUGGEDCOM RST2428P, SCALANCE XC/XR/XCM/XRM/XCH/XRH families) running SINEC OS with Linux kernel-based traffic control. System administrators managing Linux systems with custom tc/qdisc configurations. Industrial control system operators relying on network QoS mechanisms for deterministic traffic handling.
Technical summary
The Linux kernel's traffic control subsystem improperly accepts TCA_STAB (size table) parameters on non-root queueing disciplines. Most qdiscs maintain backlog counters using qdisc_pkt_len(skb), assuming packet length invariance between enqueue and dequeue operations. When TCA_STAB is applied to child qdiscs (e.g., SFQ under TBF), this assumption breaks, leading to counter corruption and system crash. The fix restricts TCA_STAB to root qdisc only, preventing the inconsistent state that enables the crash. Attack requires local access with privileges to configure network schedulers (typically CAP_NET_ADMIN).
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided updates to V3.2 or later for affected RUGGEDCOM and SCALANCE products per Siemens ProductCERT guidance
- Review network traffic control configurations to ensure TCA_STAB is only applied at root qdisc level
- Monitor for anomalous local process activity attempting to manipulate qdisc configurations
- Implement principle of least privilege for accounts with CAP_NET_ADMIN capability
- Consult Siemens ProductCERT advisory SSA-355557 for product-specific remediation timelines and configuration guidance
Evidence notes
CVE published 2025-08-12 per official CVE record. CISA advisory ICSA-25-226-07 published same date. Siemens ProductCERT advisory SSA-355557 referenced as authoritative vendor source. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H yields 5.5 MEDIUM score, consistent with local attack vector and high availability impact. CWE-476 (NULL Pointer Dereference) cited in source references.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50039 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50039
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50039 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50039
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.