PatchSiren

Linux CVE debriefs · Page 116

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Linux CVE published 2025-08-12

CVE-2024-56589

A vulnerability in the Linux kernel's hisi_sas SCSI driver, where a missing cond_resched() call in no forced preemption model kernels could cause call traces when an expander is connected to 12 high-performance SAS SSDs. The CISA advisory marks this as 'Misinformed' impact for Siemens products, indicating the vulnerability does not actually affect the listed Siemens industrial networking products (RUGGEDC [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-56586

CVE-2024-56586 describes a bug in the Linux F2FS (Flash-Friendly File System) where a specific sequence of operations—creating large files while checkpointing is disabled until space exhaustion, deleting those files, remounting to re-enable checkpointing, and then unmounting—triggers an f2fs_bug_on assertion during the f2fs_evict_inode call. This vulnerability was originally identified in the Linux kernel [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-56531

CVE-2024-56531 describes a vulnerability in the ALSA caiaq driver where `snd_card_free()` is used during USB device disconnection. This function waits for all open file descriptors to close, which can cause extended delays and potentially block upper-layer USB ioctls, leading to a soft lockup condition. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified t [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-50282

CVE-2024-50282 describes a missing size check in the `amdgpu_debugfs_gprwave_read()` function within the Linux kernel's AMDGPU DRM driver. The vulnerability could allow a buffer overflow when the size parameter exceeds 4KB. However, the CISA CSAF advisory ICSA-25-226-07 (republished 2026-02-25) explicitly marks this CVE as **Misinformed** for Siemens products, indicating the vulnerability does not actuall [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-50265

CVE-2024-50265 is a null-pointer-dereference vulnerability in the OCFS2 (Oracle Cluster File System 2) Linux kernel module, specifically within the ocfs2_xa_remove() function. The issue was discovered via Syzkaller kernel fuzzing. According to the source advisory, this CVE is marked as **Misinformed** for affected Siemens products, indicating the vulnerability does not actually impact the listed product c [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-49973

CVE-2024-49973 describes a vulnerability in the r8169 network driver affecting the RTL8125 Ethernet controller. The issue stems from added fields to the tally counter structure, which could cause the chip to perform Direct Memory Access (DMA) on these new fields and potentially write to unallocated memory. This represents a memory safety issue that could lead to system instability or memory corruption. Th [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-49903

CVE-2024-49903 is a use-after-free (UAF) vulnerability in the Linux kernel's JFS (Journaled File System) implementation, specifically within the `dbFreeBits` function in `fs/jfs/jfs_dmap.c`. The vulnerability stems from a race condition between two code paths—`dbUnmount` and `jfs_ioc_trim`—that concurrently access the `bmap` structure without proper synchronization. The fix introduces the `s_umount` lock [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-49895

CVE-2024-49895 is a buffer overflow vulnerability in the AMD display driver subsystem (drm/amd/display). The flaw exists in the cm_helper_translate_curve_to_degamma_hw_format function, where an index 'i' could access transfer function points outside valid bounds. The fix adds a bounds check to prevent out-of-bounds memory access. This vulnerability was published on 2025-08-12 and last modified on 2026-02- [truncated]

MEDIUM Linux CVE published 2025-08-12

CVE-2024-49892

CVE-2024-49892 is a divide-by-zero vulnerability in the Linux kernel's AMD display driver (drm/amd/display). The root cause was that get_bytes_per_element() could return 0 as a default value, which then became a denominator in subsequent calculations. The fix initializes the default return value to 1 instead of 0. This vulnerability was identified through Coverity static analysis, which flagged 10 separat [truncated]

MEDIUM Linux CVE published 2025-08-12

CVE-2024-49890

CVE-2024-49890 is a null pointer dereference vulnerability in the Linux kernel's AMD Power Management (drm/amd/pm) subsystem. The issue was identified by Coverity static analysis, which flagged a potential dereference of a null return value. The upstream Linux kernel fix ensures that fw_info is validated as non-null before use. Siemens has assessed this CVE as **Misinformed** for its affected industrial n [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-46822

This CVE addresses a hardening deficiency in the Linux kernel's ARM64 ACPI implementation. The function `get_cpu_for_acpi_id()` lacked proper validation when encountering missing CPU entries in the ACPI tables, which could lead to undefined behavior or system instability on ARM64 platforms using ACPI firmware. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has asses [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-46804

CVE-2024-46804 is a vulnerability in the Linux kernel's AMD display driver (drm/amd/display) related to an array index check for HDCP DDC access. The vulnerability description indicates a missing bounds check that could lead to improper memory access during HDCP (High-bandwidth Digital Content Protection) DDC (Display Data Channel) operations. The CVE was published on August 12, 2025, and last modified on [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-44969

This CVE describes a vulnerability in the s390/sclp (System z Service Call Logical Processor) Linux kernel subsystem. The issue involves a potential data corruption scenario that could occur if a Store Data operation is interrupted and the subsequent halt attempt fails. The resolution prevents the release of data buffers in such failure cases to maintain data integrity. The vulnerability was published on [truncated]

MEDIUM Linux CVE published 2025-08-12

CVE-2024-44949

This CVE addresses a DMA corruption vulnerability in the PA-RISC (parisc) Linux kernel architecture. The root cause is an insufficient ARCH_DMA_MINALIGN value of 16 bytes, which can result in two unrelated 16-byte allocations sharing the same cache line. When one allocation is written via DMA and the other via cached write, DMA-written data may be corrupted. The vulnerability was published on 2025-08-12 a [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-43882

CVE-2024-43882 is a HIGH severity vulnerability (CVSS 7.0) affecting Siemens industrial networking products, specifically the RUGGEDCOM RST2428P (6GK6242-6PA00) and SCALANCE switch families. The vulnerability involves improper input validation (CWE-20) in the exec function, which may allow execution to gain unintended privileges. The vulnerability was published on August 12, 2025, and the advisory was sub [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-42152

CVE-2024-42152 describes a possible resource leak in the Linux kernel NVMe-oF target (nvmet) subsystem that occurs when destroying a controller during queue pair (QP) establishment. The vulnerability stems from improper cleanup handling during a race condition between controller teardown and QP setup operations. A CVSS v3.1 score of 7.1 (HIGH) indicates significant impact potential, though the specific at [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-41078

A vulnerability in the Btrfs filesystem's quota group (qgroup) implementation can cause a quota root leak when quota disable operations fail. This resource leak occurs in the Linux kernel's Btrfs code and may affect systems where quota management is enabled and subsequently disabled. The issue stems from improper cleanup of quota root structures when the disable operation encounters an error condition, po [truncated]

MEDIUM Linux CVE published 2025-08-12

CVE-2024-41004

CVE-2024-41004 is a Linux kernel tracing subsystem issue where kprobes and synthetic event generation test modules, when compiled as built-in rather than loadable modules, leave event file references permanently locked in the kernel. The root cause stems from the module design pattern: these test modules acquire event file references during initialization and release them during exit. When built into the [truncated]

MEDIUM Linux CVE published 2025-08-12

CVE-2024-40995

CVE-2024-40995 describes a possible infinite loop condition in the Linux kernel's network traffic control subsystem, specifically within the `tcf_idr_check_alloc()` function in `net/sched/act_api.c`. This vulnerability resides in the kernel's traffic classifier action API, which is used to manage packet filtering and traffic shaping rules. An infinite loop in this context could lead to a denial-of-service [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-40987

This CVE describes a UBSAN (Undefined Behavior Sanitizer) warning in the Linux kernel's AMDGPU driver, specifically in the kv_dpm.c file related to dynamic power management for Kabini/Temash APUs. The source advisory (ICSA-25-226-07) marks this vulnerability as 'Misinformed' for the listed Siemens products, indicating the CVE was initially thought to affect these products but was later determined not to b [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-36894

This CVE addresses a race condition vulnerability in the Linux kernel's USB gadget subsystem, specifically within the Function Filesystem (f_fs) driver. The vulnerability involves a race between `aio_cancel()` and AIO request completion operations. According to the source advisory, this vulnerability has been assessed as **Misinformed** for the Siemens products listed, indicating that the products are not [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2024-36886

A use-after-free (UAF) vulnerability exists in the Linux kernel's Transparent Inter-Process Communication (TIPC) protocol implementation, specifically within the `tipc_buf_append()` error path. The vulnerability was reported by Sam Page (sam4k) working with Trend Micro Zero Day Initiative. The issue occurs when handling socket buffer (skb) operations during error conditions, where improper memory manageme [truncated]

MEDIUM Linux CVE published 2025-08-12

CVE-2024-33621

A vulnerability in the Linux kernel's IPvlan network driver could allow a local, privileged attacker to cause a denial of service (DoS) condition. The flaw exists in the `ipvlan_process_v4_outbound` and `ipvlan_process_v6_outbound` functions, which improperly use `skb->sk` (socket buffer socket pointer) during packet processing. This can lead to a NULL pointer dereference or use-after-free condition, resu [truncated]

Review Linux CVE published 2025-08-12

CVE-2024-26790

A vulnerability in the Linux kernel's Freescale QDMA engine driver (fsl-qdma) could cause System-on-Chip (SoC) hangs when performing 16-byte unaligned memory reads. The issue was resolved in the Linux kernel. Siemens has assessed this CVE as 'Misinformed' for its affected industrial networking products, indicating the vulnerability does not apply to these specific product configurations.

MEDIUM Linux CVE published 2025-08-12

CVE-2024-26671

A race condition in the Linux kernel's block multi-queue (blk-mq) subsystem can cause I/O operations to hang indefinitely. The vulnerability stems from a synchronization issue in the sbitmap (sparse bitmap) wakeup mechanism used for managing I/O request tags. When the race condition triggers, pending I/O requests may never be processed, leading to system unavailability or degraded performance in storage-d [truncated]

HIGH Linux CVE published 2025-08-12

CVE-2023-52654

This CVE addresses a vulnerability in the Linux kernel's io_uring subsystem related to AF_UNIX sockets. The fix disables the ability to send io_uring file descriptors over Unix domain sockets, which could potentially be exploited to manipulate or corrupt kernel memory structures. The vulnerability was resolved by preventing this specific capability in the kernel's networking code. Siemens has assessed thi [truncated]

Review Linux CVE published 2025-08-12

CVE-2023-52475

A use-after-free vulnerability in the Linux kernel's Griffin PowerMate USB input driver (powermate) was resolved via a code fix. The flaw existed in the powermate_config_complete callback function. Siemens has assessed this CVE as not affecting its RUGGEDCOM RST2428P and SCALANCE X-family industrial networking products, reclassifying them from affected to known not affected in subsequent advisory revision [truncated]

CRITICAL Linux CVE published 2025-08-12

CVE-2022-48829

CVE-2022-48829 is a Linux kernel NFSD issue in NFSv3 SETATTR and CREATE handling for large file sizes. The bug can corrupt or silently alter incoming size values when they exceed the signed 64-bit range, which is unexpected behavior for clients and can affect NFS server availability and correctness. NVD rates the issue as medium severity, with local, low-privilege conditions required.

CRITICAL Linux CVE published 2025-08-12

CVE-2022-48828

CVE-2022-48828 is a Linux kernel NFSD bug where an NFS file-size value can be copied into a signed 64-bit iattr::ia_size field without first checking whether the unsigned value exceeds S64_MAX. The result is an underflow in nfsd_setattr(), with availability impact only per the CVSS vector. The NVD record and linked kernel patches describe the issue as fixed in the common setattr path used by NFSv3 and NFSv4 handling.

HIGH Linux CVE published 2025-08-12

CVE-2022-48827

CVE-2022-48827 is a Linux kernel NFS server bug where a READ request near OFFSET_MAX can overflow internal offset handling, leading the server to return EINVAL and the client to retry indefinitely. The fix changes out-of-range READ behavior to complete as a short read with EOF and ensures wire offsets are converted safely to loff_t before kernel checks.