PatchSiren cyber security CVE debrief
CVE-2024-53097 Siemens CVE debrief
CVE-2024-53097 is a low-severity vulnerability (CVSS 3.3) in the Linux kernel's memory management subsystem, specifically affecting the krealloc function. The issue involves a Memory Tagging Extension (MTE) false alarm in __do_krealloc, which can trigger incorrect memory safety warnings. Siemens has identified this vulnerability as affecting multiple industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE switch families. The vulnerability requires local access and low privileges to exploit, with potential for limited availability impact. Siemens has released updates to address this issue, with fixes available in version 3.2 or later for affected products.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P switches or SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 and XCM-/XRM-/XCH-/XRH-300 family switches in industrial environments should prioritize patching to prevent potential service disruptions from false MTE alarms.
Technical summary
The vulnerability exists in the Linux kernel's mm/krealloc.c implementation where the __do_krealloc function generates false positive MTE (Memory Tagging Extension) alarms. MTE is an ARM64 security feature that tags memory allocations to detect use-after-free and buffer overflow conditions. The false alarm condition can cause legitimate memory reallocation operations to trigger incorrect security warnings. This affects Siemens industrial networking products that incorporate the vulnerable kernel code through SINEC OS. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L) indicates a local attack vector requiring low privileges, with no confidentiality or integrity impact and low availability impact.
Defensive priority
LOW
Recommended defensive actions
- Apply vendor-provided updates to version 3.2 or later for affected Siemens RUGGEDCOM and SCALANCE products
- Review Siemens ProductCERT advisory SSA-355557 for specific product configuration guidance
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor for additional vendor guidance on SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configurations
Evidence notes
CVE published 2025-08-12 per CISA CSAF advisory ICSA-25-226-07. Modified 2026-02-25. Advisory republished by CISA based on Siemens ProductCERT SSA-355557.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-53097 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-53097
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-53097 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-53097
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.