PatchSiren cyber security CVE debrief
CVE-2025-40280 Siemens CVE debrief
A use-after-free vulnerability exists in the Linux kernel's tipc_mon_reinit_self() function. The vulnerability is triggered when the function iterates over the tipc_net(net)->monitors[] array without holding the RTNL lock. This can lead to a use-after-free error when the array is accessed concurrently by another thread. The affected product is RUGGEDCOM RST2428P (6GK6242-6PA00) from Siemens. Linux kernel users, administrators of systems using the affected product, and those responsible for maintaining and securing Industrial Control Systems should assess their exposure and apply remediation. The vulnerability has been resolved in later kernel versions.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-02
- Original CVE updated
- 2026-07-07
- Advisory published
- 2026-06-02
- Advisory updated
- 2026-07-07
Who should care
Linux kernel users, administrators of systems using the affected product RUGGEDCOM RST2428P (6GK6242-6PA00), and those responsible for maintaining and securing Industrial Control Systems should assess their exposure and apply remediation.
Why it matters
A use-after-free vulnerability in the Linux kernel's tipc_mon_reinit_self() function requires verification of exposure and application of remediation to prevent potential errors.
- Verify Linux kernel versions used in the environment to determine exposure
- Assess the risk of use-after-free errors in the tipc_mon_reinit_self() function
- Apply remediation by updating to V4.0 or later version of the affected product
- Review and implement recommended practices for Industrial Control Systems
Technical summary
The Linux kernel's tipc_mon_reinit_self() function has a use-after-free vulnerability. The function iterates over the tipc_net(net)->monitors[] array without holding the RTNL lock, which can lead to a use-after-free error when the array is accessed concurrently by another thread. The vulnerability has been resolved in later kernel versions. The affected product is RUGGEDCOM RST2428P (6GK6242-6PA00) from Siemens, and users should assess their exposure and apply remediation as needed. The vulnerability was reported by syzbot.
Defensive priority
Medium priority should be given to assessing exposure and applying remediation, as the vulnerability has been resolved in later kernel versions.
Recommended defensive actions
- Assess exposure of Linux kernel versions used in the environment
- Verify if the affected product RUGGEDCOM RST2428P (6GK6242-6PA00) is in use and apply remediation
- Update to V4.0 or later version of the affected product
- Review and implement recommended practices for Industrial Control Systems
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The vulnerability was reported by syzbot and has been resolved in later kernel versions. The affected product is RUGGEDCOM RST2428P (6GK6242-6PA00) from Siemens. There is limited information available about the vulnerability, and defenders should verify the exposure of their systems and apply remediation as needed. The CVE record was published on 2026-06-02T00:00:00.000Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40280 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40280
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40280 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40280
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2025-40280
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-253495.json
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-253495.html
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.