These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
This CVE addresses a path traversal vulnerability in the Linux kernel's firmware_loader subsystem. The issue arises when firmware file names contain string components passed through from a device or semi-privileged userspace, potentially allowing unauthorized file access outside intended directories. Siemens has identified affected products in its industrial networking portfolio, including RUGGEDCOM RST24 [truncated]
CVE-2024-47740 is a medium-severity vulnerability (CVSS 5.5) in the Linux F2FS filesystem affecting Siemens industrial networking products. The flaw exists in F2FS atomic write ioctls that check inode_owner_or_capable() without requiring FMODE_WRITE, bypassing Linux Security Module (LSM) enforcement. When a caller's FSUID matches the inode's UID, the check returns true immediately, preventing SELinux or L [truncated]
CVE-2024-47739 is a medium-severity vulnerability in the Linux kernel's padata subsystem, where a missing integer wrap-around check on the seq_nr counter can cause a deadlock when the sequence number overflows. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 and XCM-/XRM-/XCH-/XRH-300 [truncated]
This CVE addresses a memory management vulnerability in the Linux kernel's NFS server (nfsd) implementation. The issue involves a missing cache_put() call when xdr_reserve_space() returns NULL, which could lead to resource leaks. The vulnerability was resolved by ensuring proper cleanup in error paths. Siemens has assessed this CVE as 'Misinformed' for their affected product lines, indicating the vulnerab [truncated]
CVE-2024-47735 is a MEDIUM-severity vulnerability (CVSS 5.5) affecting the RDMA/hns driver in the Linux kernel, specifically impacting Siemens SIMATIC S7-1500 TM MFP's GNU/Linux subsystem. The flaw involves incorrect locking primitives: spin_lock_irq()/spin_unlock_irq() were used while spin_lock_irqsave()/spin_unlock_irqrestore() was already held, which can lead to deadlock conditions or interrupt handlin [truncated]
This CVE addresses an out-of-bounds access vulnerability in the JFS (Journaled File System) implementation within the Linux kernel. The vulnerability exists in the `dbNextAG()` and `diAlloc()` functions where insufficient bounds checking on allocation group (AG) values could lead to memory corruption when processing malformed or 'polluted' JFS images. Specifically, `dbNextAG()` lacked validation when `bmp [truncated]
CVE-2024-47718 is a use-after-free (UAF) vulnerability in the rtw88 Wi-Fi driver affecting Linux kernel systems. The flaw occurs when firmware loading is not properly synchronized during USB initialization and disconnection, potentially allowing memory corruption. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting certain industrial [truncated]
CVE-2024-47713 is a vulnerability in the Linux kernel's mac80211 wireless networking subsystem, specifically within the ieee80211_do_stop() function. The issue stems from a two-phase socket buffer (skb) reclamation implementation intended to avoid warnings and potential problems when calling __dev_queue_xmit() with interrupts disabled. This vulnerability was published on August 12, 2025, and last modified [truncated]
CVE-2024-47712 describes a vulnerability in the wilc1000 Wi-Fi driver related to RCU (Read-Copy-Update) dereference handling in the `wilc_parse_join_bss_param` function. The issue involves storing the TSF (Timing Synchronization Function) value in a local variable before releasing the RCU lock, which is intended to prevent use-after-free errors. This vulnerability was published on August 12, 2025, and las [truncated]
CVE-2024-47710 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's sock_map subsystem, specifically within the sock_hash_free() function. The issue stems from the addition of a cond_resched() call intended to prevent CPU soft lockups when destroying maps with a large number of buckets. This vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has [truncated]
A vulnerability in the Linux kernel's Controller Area Network (CAN) Broadcast Manager (BCM) protocol implementation can trigger a warning condition and unnecessary proc entry removal when socket operations occur on unregistered devices. The issue manifests when a socket's connected device is unregistered, and the socket is subsequently closed without issuing a second connect() call. This leads to the bcm_ [truncated]
A use-after-free (UAF) vulnerability exists in the Linux kernel's Budget Fair Queueing (BFQ) I/O scheduler. The flaw occurs when I/O from a process traverses a merge chain of BFQ queues (bfqq), causing the code to incorrectly associate a bfqq with a Block I/O Context (BIC) that no longer owns it. Specifically, when Process 1 obtains bfqq2 from BIC1, then acquires bfqq3 through a merge chain, the I/O is ul [truncated]
This CVE addresses a vulnerability in the Linux kernel's block layer where an invalid pointer dereference could occur in the blk_add_partition() function. The issue stemmed from a code refactoring that modified error handling to separately process -ENXIO errors, inadvertently creating a code path where md_autodetect_dev() could be called without verifying that the partition pointer was valid. The vulnerab [truncated]
A vulnerability in the Linux kernel's ext4 filesystem could allow an out-of-bounds (OOB) memory access when the system.data extended attribute changes underneath the filesystem. This issue has been resolved in the upstream Linux kernel. Siemens has identified this vulnerability as affecting multiple industrial networking products that incorporate the vulnerable Linux kernel component, including RUGGEDCOM [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's nilfs2 filesystem driver, specifically within the nilfs_btree_insert() function. The issue arises when a corrupted nilfs2 filesystem image presents an inconsistent b-tree structure: a b-tree root node with height greater than 2 (level > 1) but zero child nodes. Under these conditions, nilfs_btree_do_lookup() fails to initialize path[x]. [truncated]
CVE-2024-47698 is an out-of-bounds access vulnerability in the Linux kernel's RTL2832 DVB frontend driver. The flaw occurs when the rtl2832_pid_filter parameter exceeds 31 without proper bounds verification, potentially leading to memory corruption. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-5 [truncated]
CVE-2024-47697 is an out-of-bounds write vulnerability in the Linux kernel's RTL2830 DVB frontend driver. The flaw exists in the `rtl2830_pid_filter` function where an incorrect boundary check (`index > 32` instead of `index >= 32`) allows an index value of 32 to be processed. Since `dev->filters` is a 32-bit value, valid bit indices range from 0-31; an index of 32 causes access to a non-existent 33rd bit [truncated]
A use-after-free vulnerability in the Linux kernel's RDMA/iwcm (iWARP Connection Manager) subsystem, affecting Siemens industrial networking products. The flaw stems from improper workqueue handling where `flush_workqueue()` is called on `iwcm_wq` without the `WQ_MEM_RECLAIM` flag, violating kernel workqueue forward-progress guarantees and potentially causing deadlocks. This is a local privilege escalatio [truncated]
A null pointer dereference vulnerability exists in the Linux kernel's NFS server (nfsd) component. The flaw occurs when a corrupted main.sqlite database in /var/lib/nfs/nfsdcld/ results in a namelen value of 0, causing memdup_user() to return ZERO_SIZE_PTR. Subsequent access to name.data in nfs4_client_to_reclaim() triggers a null pointer dereference. The vulnerability has been resolved by returning -EINV [truncated]
A critical vulnerability in the Linux kernel's netfilter IPv6 rejection handling allows uninitialized memory to be transmitted in TCP reset packets. The flaw resides in nf_reject_ip6_tcphdr_put(), which failed to zero-initialize the TCP header before transmission, potentially leaking kernel memory contents through the four reserved TCP header bits (th->res1). This was discovered by syzbot and reported via [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's TCP stack within the tcp_rto_delta_us() function. The flaw occurs when tcp_rearm_rto() is invoked with a NULL socket buffer (skb), leading to a kernel crash. This vulnerability was observed in production environments running Ubuntu 20.04.6 with kernel 5.4.0-174-generic, particularly affecting Ceph storage workloads. The crash manifests [truncated]
A race condition vulnerability exists in the Linux kernel's Virtual File System (VFS) layer, specifically between `evict_inodes()` and `find_inode()`/`iput()` operations. This flaw affects Siemens industrial networking products running SINEC OS, which incorporates the vulnerable Linux kernel component. The vulnerability was published on August 12, 2025, with subsequent advisory updates through February 25 [truncated]
A state management vulnerability in the nilfs2 filesystem's log writing error path. The issue occurs when the log writing function encounters an error, potentially leading to improper state management. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA published advisory ICSA-25-226-07 on August 12, 2 [truncated]
A race condition in the Linux kernel's generic radix tree implementation (lib/generic-radix-tree.c) affects Siemens industrial networking products running SINEC OS. The vulnerability in __genradix_ptr_alloc() can lead to denial of service conditions. Siemens has released firmware updates to address this issue in affected RUGGEDCOM and SCALANCE product families.
CVE-2024-47663 is a division-by-zero vulnerability in the Linux kernel's AD9834 Direct Digital Synthesis (DDS) driver, specifically within the `ad9834_write_frequency()` function in the staging IIO frequency subsystem. The flaw occurs when `clk_get_rate()` returns zero, which is not properly handled before calling `ad9834_calc_freqreg()`, leading to a division by zero. The existing check `if (fout > (clk_ [truncated]
A race condition in the Linux kernel's fsnotify subsystem can cause soft lockups on systems with directories containing many dentries. The vulnerability stems from contention on inode->i_lock when __fsnotify_update_child_dentry_flags() calls race between fsnotify_recalc_mask() and __fsnotify_parent(). Siemens has identified affected industrial networking products running SINEC OS that incorporate the vuln [truncated]
A vulnerability in the Smack Linux Security Module's TCP/IPv4 labeling implementation allows packets to be incorrectly labeled, potentially enabling unauthorized data writing from one security label to another. This flaw affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE XC/XR/XCM/XRM/XCH/XRH families. The vulnerability stems from improper han [truncated]
A medium-severity deadlock vulnerability exists in the Linux kernel's DMA debug subsystem, affecting Siemens industrial networking products running SINEC OS. The flaw involves improper lock ordering between radix_lock() and dma_hash_entry[idx].lock, which can trigger a deadlock when the DMA debug API is invoked while holding rq_lock(). This local attack vector requires low privileges and no user interacti [truncated]
A vulnerability in the Linux kernel's User-Mode Linux (UML) subsystem could allow local attackers to cause denial-of-service conditions. The flaw exists in the `setup_one_line()` function where an uninitialized pointer (`*error_out`) may be printed in certain error paths, potentially leading to information disclosure or system instability. Siemens has identified this vulnerability as affecting multiple in [truncated]
CVE-2024-46840 addresses improper error handling in the Linux kernel's Btrfs filesystem, specifically during snapshot deletion operations. The vulnerability stems from multiple instances where BUG_ON(refs == 0) assertions were used without adequate locking or corruption validation, potentially causing system crashes or inconsistent state. The fix converts these fatal assertions to proper error returns (-E [truncated]