PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-56619 Siemens CVE debrief

This CVE describes a vulnerability in the nilfs2 filesystem where corrupted inode i_size values can lead to out-of-bounds memory access or use-after-free conditions when searching directory records. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting their RUGGEDCOM RST2428P and SCALANCE product families running SINEC OS, though the source advisory marks the impact assessment as 'Misinformed' for the affected products. The vulnerability originates in the Linux kernel's nilfs2 filesystem implementation rather than Siemens proprietary code. No CVSS score or severity rating is available in the source data. The CISA advisory ICSA-25-226-07 was republished on 2026-02-25 based on Siemens ProductCERT advisory SSA-355557, which corrected the affected products list in previous revisions.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, or SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices with SINEC OS should monitor for Siemens security updates. ICS/OT security teams should assess exposure of nilfs2 filesystems on deployed devices.

Technical summary

The nilfs2 filesystem in the Linux kernel contains a vulnerability triggered when directory inode i_size values are corrupted to large values. During directory record search operations, this can cause memory access outside the folio/page range or use-after-free conditions detectable under KASAN. Siemens products running SINEC OS incorporate this kernel component. The vulnerability requires local filesystem access or existing filesystem corruption to trigger.

Defensive priority

medium

Recommended defensive actions

  • Review Siemens ProductCERT advisory SSA-355557 for current affected product status and patch availability
  • Verify nilfs2 filesystem is not exposed on affected Siemens devices in operational deployments
  • Apply kernel updates from Siemens when available for SINEC OS-based products
  • Monitor CISA ICS advisories for updates to ICSA-25-226-07
  • Implement network segmentation for ICS/OT devices per CISA recommended practices

Evidence notes

Source CISA CSAF advisory ICSA-25-226-07 marks impact as 'Misinformed' for affected Siemens products. Advisory revision history shows multiple corrections to affected products list, with final republication on 2026-02-25 based on Siemens SSA-355557.

Official resources

2025-08-12