These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2024-49892 is a divide-by-zero vulnerability in the Linux kernel's AMD display driver (drm/amd/display). The root cause was that get_bytes_per_element() could return 0 as a default value, which then became a denominator in subsequent calculations. The fix initializes the default return value to 1 instead of 0. This vulnerability was identified through Coverity static analysis, which flagged 10 separat [truncated]
CVE-2024-49890 is a null pointer dereference vulnerability in the Linux kernel's AMD Power Management (drm/amd/pm) subsystem. The issue was identified by Coverity static analysis, which flagged a potential dereference of a null return value. The upstream Linux kernel fix ensures that fw_info is validated as non-null before use. Siemens has assessed this CVE as **Misinformed** for its affected industrial n [truncated]
This CVE addresses a hardening deficiency in the Linux kernel's ARM64 ACPI implementation. The function `get_cpu_for_acpi_id()` lacked proper validation when encountering missing CPU entries in the ACPI tables, which could lead to undefined behavior or system instability on ARM64 platforms using ACPI firmware. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has asses [truncated]
CVE-2024-46804 is a vulnerability in the Linux kernel's AMD display driver (drm/amd/display) related to an array index check for HDCP DDC access. The vulnerability description indicates a missing bounds check that could lead to improper memory access during HDCP (High-bandwidth Digital Content Protection) DDC (Display Data Channel) operations. The CVE was published on August 12, 2025, and last modified on [truncated]
This CVE describes a vulnerability in the s390/sclp (System z Service Call Logical Processor) Linux kernel subsystem. The issue involves a potential data corruption scenario that could occur if a Store Data operation is interrupted and the subsequent halt attempt fails. The resolution prevents the release of data buffers in such failure cases to maintain data integrity. The vulnerability was published on [truncated]
This CVE addresses a DMA corruption vulnerability in the PA-RISC (parisc) Linux kernel architecture. The root cause is an insufficient ARCH_DMA_MINALIGN value of 16 bytes, which can result in two unrelated 16-byte allocations sharing the same cache line. When one allocation is written via DMA and the other via cached write, DMA-written data may be corrupted. The vulnerability was published on 2025-08-12 a [truncated]
CVE-2024-43882 is a HIGH severity vulnerability (CVSS 7.0) affecting Siemens industrial networking products, specifically the RUGGEDCOM RST2428P (6GK6242-6PA00) and SCALANCE switch families. The vulnerability involves improper input validation (CWE-20) in the exec function, which may allow execution to gain unintended privileges. The vulnerability was published on August 12, 2025, and the advisory was sub [truncated]
CVE-2024-42152 describes a possible resource leak in the Linux kernel NVMe-oF target (nvmet) subsystem that occurs when destroying a controller during queue pair (QP) establishment. The vulnerability stems from improper cleanup handling during a race condition between controller teardown and QP setup operations. A CVSS v3.1 score of 7.1 (HIGH) indicates significant impact potential, though the specific at [truncated]
A vulnerability in the Btrfs filesystem's quota group (qgroup) implementation can cause a quota root leak when quota disable operations fail. This resource leak occurs in the Linux kernel's Btrfs code and may affect systems where quota management is enabled and subsequently disabled. The issue stems from improper cleanup of quota root structures when the disable operation encounters an error condition, po [truncated]
CVE-2024-41004 is a Linux kernel tracing subsystem issue where kprobes and synthetic event generation test modules, when compiled as built-in rather than loadable modules, leave event file references permanently locked in the kernel. The root cause stems from the module design pattern: these test modules acquire event file references during initialization and release them during exit. When built into the [truncated]
CVE-2024-40995 describes a possible infinite loop condition in the Linux kernel's network traffic control subsystem, specifically within the `tcf_idr_check_alloc()` function in `net/sched/act_api.c`. This vulnerability resides in the kernel's traffic classifier action API, which is used to manage packet filtering and traffic shaping rules. An infinite loop in this context could lead to a denial-of-service [truncated]
This CVE describes a UBSAN (Undefined Behavior Sanitizer) warning in the Linux kernel's AMDGPU driver, specifically in the kv_dpm.c file related to dynamic power management for Kabini/Temash APUs. The source advisory (ICSA-25-226-07) marks this vulnerability as 'Misinformed' for the listed Siemens products, indicating the CVE was initially thought to affect these products but was later determined not to b [truncated]
This CVE addresses a race condition vulnerability in the Linux kernel's USB gadget subsystem, specifically within the Function Filesystem (f_fs) driver. The vulnerability involves a race between `aio_cancel()` and AIO request completion operations. According to the source advisory, this vulnerability has been assessed as **Misinformed** for the Siemens products listed, indicating that the products are not [truncated]
A use-after-free (UAF) vulnerability exists in the Linux kernel's Transparent Inter-Process Communication (TIPC) protocol implementation, specifically within the `tipc_buf_append()` error path. The vulnerability was reported by Sam Page (sam4k) working with Trend Micro Zero Day Initiative. The issue occurs when handling socket buffer (skb) operations during error conditions, where improper memory manageme [truncated]
A vulnerability in the Linux kernel's IPvlan network driver could allow a local, privileged attacker to cause a denial of service (DoS) condition. The flaw exists in the `ipvlan_process_v4_outbound` and `ipvlan_process_v6_outbound` functions, which improperly use `skb->sk` (socket buffer socket pointer) during packet processing. This can lead to a NULL pointer dereference or use-after-free condition, resu [truncated]
A vulnerability in the Linux kernel's Freescale QDMA engine driver (fsl-qdma) could cause System-on-Chip (SoC) hangs when performing 16-byte unaligned memory reads. The issue was resolved in the Linux kernel. Siemens has assessed this CVE as 'Misinformed' for its affected industrial networking products, indicating the vulnerability does not apply to these specific product configurations.
A race condition in the Linux kernel's block multi-queue (blk-mq) subsystem can cause I/O operations to hang indefinitely. The vulnerability stems from a synchronization issue in the sbitmap (sparse bitmap) wakeup mechanism used for managing I/O request tags. When the race condition triggers, pending I/O requests may never be processed, leading to system unavailability or degraded performance in storage-d [truncated]
This CVE addresses a vulnerability in the Linux kernel's io_uring subsystem related to AF_UNIX sockets. The fix disables the ability to send io_uring file descriptors over Unix domain sockets, which could potentially be exploited to manipulate or corrupt kernel memory structures. The vulnerability was resolved by preventing this specific capability in the kernel's networking code. Siemens has assessed thi [truncated]
A use-after-free vulnerability in the Linux kernel's Griffin PowerMate USB input driver (powermate) was resolved via a code fix. The flaw existed in the powermate_config_complete callback function. Siemens has assessed this CVE as not affecting its RUGGEDCOM RST2428P and SCALANCE X-family industrial networking products, reclassifying them from affected to known not affected in subsequent advisory revision [truncated]
CVE-2022-48829 is a Linux kernel NFSD issue in NFSv3 SETATTR and CREATE handling for large file sizes. The bug can corrupt or silently alter incoming size values when they exceed the signed 64-bit range, which is unexpected behavior for clients and can affect NFS server availability and correctness. NVD rates the issue as medium severity, with local, low-privilege conditions required.
CVE-2022-48828 is a Linux kernel NFSD bug where an NFS file-size value can be copied into a signed 64-bit iattr::ia_size field without first checking whether the unsigned value exceeds S64_MAX. The result is an underflow in nfsd_setattr(), with availability impact only per the CVSS vector. The NVD record and linked kernel patches describe the issue as fixed in the common setattr path used by NFSv3 and NFSv4 handling.
CVE-2022-48827 is a Linux kernel NFS server bug where a READ request near OFFSET_MAX can overflow internal offset handling, leading the server to return EINVAL and the client to retry indefinitely. The fix changes out-of-range READ behavior to complete as a short read with EOF and ensures wire offsets are converted safely to loff_t before kernel checks.
CVE-2021-47316 is a Linux kernel nfsd NULL dereference issue in the nfs3svc_encode_getaclres XDR encoder. The NVD record lists Linux kernel versions 5.13 through before 5.13.4 as affected. The supplied description says that in error cases the dentry may be NULL, and that the encoder previously performed extra checks before later simplification. The published CVSS vector indicates a local, low-privilege pa [truncated]
CVE-2023-0386 is a Linux kernel vulnerability described as an improper ownership management issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-17, which means it is considered known to be exploited and should be prioritized for remediation. The supplied corpus does not include deeper technical detail, so this debrief stays at a high level and focuses on defensive response.
CVE-2024-26596 is a Linux kernel availability issue in DSA netdevice event handling. The vulnerability was published on 2024-02-23 and describes a case where code dereferenced netdev_priv() before confirming the device was actually a DSA user device. On netdevices with zero private data size, such as the dummy interface, this can produce an out-of-bounds read and a kernel oops during NETDEV_PRECHANGEUPPER [truncated]
CVE-2024-24855 is a Linux kernel vulnerability published on 2024-02-05 and later modified on 2026-05-12 in NVD. The issue is a race condition in lpfc_unregister_fcf_rescan() that can lead to a null pointer dereference, with possible impact ranging from a kernel crash to denial of service. NVD classifies the issue as medium severity, and the supplied vector indicates local access, low privileges, and user [truncated]
CVE-2024-53197 is a Linux kernel out-of-bounds access vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-04-09. Because it is on the KEV list, defenders should treat it as actively exploited or otherwise significant enough to require prompt mitigation, even though the provided corpus does not include a CVSS score or detailed impact analysis. The most important action is t [truncated]
CVE-2024-53150 is a Linux Kernel out-of-bounds read vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-04-09. Because it is on the KEV list, organizations should treat it as a priority exposure and follow vendor guidance for any Linux-based systems and downstream products that rely on the kernel.
CVE-2023-35001 is a Linux kernel nftables out-of-bounds read/write issue that CISA mapped to ABB M2M Gateway ARM600 and ABB M2M Gateway SW. The advisory says the flaw can lead to local user privilege escalation and assigns CVSS 7.8 (HIGH). CISA published the advisory on 2025-04-07. For defenders, the most important takeaway is that this is a high-impact local-privilege issue affecting specific ABB gateway [truncated]
CVE-2022-3564 is a Linux kernel Bluetooth use-after-free issue that ABB lists as affecting ARM600 and ABB M2M Gateway SW. In the ABB/CISA advisory published on 2025-04-07, the affected ranges are ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. The reported impact is potential data leakage or denial of service. The CVSS vector provided in the source is 6.8 (Medium), while th [truncated]