PatchSiren

siemens CVE debriefs · Page 24

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-44935

CVE-2024-44935 is a null pointer dereference vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) subsystem, specifically within the `reuseport_add_sock()` function. The flaw occurs when a race condition between socket creation and closure leads to accessing a cleared `sk_reuseport_cb` pointer. An attacker with local access could potentially trigger this condition to cause a den [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-43908

CVE-2024-43908 describes a null pointer dereference vulnerability in the Linux kernel's AMDGPU driver, specifically within the RAS (Reliability, Availability, and Serviceability) manager component. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens ProductCERT issued advisory SSA-355557 addressing this vulnerability in third-party components used within SIN [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-43907

CVE-2024-43907 describes a null pointer dereference in the `apply_state_adjust_rules` function within the `drm/amdgpu/pm` kernel driver. The vulnerability was originally published on 2025-08-12 and last modified on 2026-02-25. According to the CISA CSAF advisory ICSA-25-226-07, Siemens has assessed this CVE as **Misinformed** for the affected product lines, indicating that the vulnerability does not actua [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-43894

A null pointer dereference vulnerability exists in the Linux kernel's Direct Rendering Manager (DRM) client subsystem. Specifically, in the `drm_client_modeset_probe()` function, a failure of `drm_mode_duplicate()` can return NULL, which was not properly checked before subsequent dereference. The vulnerability was remediated by adding an explicit NULL check. The issue affects Siemens industrial networking [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43893

A divide-by-zero vulnerability exists in the Linux serial core subsystem when the TIOCSSERIAL ioctl is called with an invalid baud_base parameter. The flaw stems from a missing validation check for uartclk being zero, which can trigger a divide-by-zero error. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switch [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43890

CVE-2024-43890 is a MEDIUM severity vulnerability (CVSS 5.5) in the Linux kernel tracing subsystem, specifically an overflow in get_free_elt() that can lead to infinite loops and CPU hangs when the tracing map becomes full. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this vulnerability as affecting certain industrial networking products running SIN [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43889

CVE-2024-43889 is a divide-by-zero vulnerability in the Linux kernel's padata subsystem, specifically in the padata_mt_helper() function during system bootup. The flaw occurs when chunk_size is uninitialized and evaluates to zero, causing a potential crash condition. This vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens ProductCERT issued advisory SSA-355557 [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43883

CVE-2024-43883 is a vulnerability in the Linux kernel's USB Virtual Host Controller Interface (vhci-hcd) driver. The flaw occurs when the driver drops references to objects before obtaining new ones, potentially resulting in use-after-free conditions through stale pointer dereferences. This vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has identified this [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43880

CVE-2024-43880 is a MEDIUM-severity vulnerability (CVSS 5.5) affecting the mlxsw (Mellanox switch) driver in the Linux kernel, specifically within the spectrum_acl_erp component. The issue involves an object nesting warning that could lead to misinformed system behavior. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43879

CVE-2024-43879 is a vulnerability in the Linux kernel's cfg80211 wireless configuration subsystem. The issue stems from an unhandled case in the `cfg80211_calculate_bitrate_he()` function, specifically the `NL80211_RATE_INFO_HE_RU_ALLOC_2x996` resource unit allocation value for HE (High Efficiency/Wi-Fi 6) rate calculations. When this value is encountered, the function fails to process it, resulting in a [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43871

A memory leak vulnerability exists in the Linux kernel's device resource management (devres) subsystem, specifically within the devm_free_percpu() API. The flaw occurs because devm_free_percpu() incorrectly uses devres_destroy() instead of devres_release() when freeing per-CPU memory allocated via devm_alloc_percpu(). This causes the memory to not be properly released, leading to resource exhaustion over [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-43867

This CVE describes a refcount underflow vulnerability in the drm/nouveau prime subsystem of the Linux kernel. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. According to the CISA CSAF advisory ICSA-25-226-07, this CVE was included in a Siemens ProductCERT advisory (SSA-355557) concerning third-party components in SINEC OS. However, the advisory's threat assessment categoriz [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-43861

CVE-2024-43861 is a memory leak vulnerability in the Linux kernel's qmi_wwan USB network driver, specifically affecting non-IP packets. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens ProductCERT issued advisory SSA-355557 addressing this issue in their SINEC OS-based products, including the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA republished this adv [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-43098

CVE-2024-43098 is a medium-severity (CVSS 5.5) deadlock vulnerability in the Linux kernel's I3C (Improved Inter-Integrated Circuit) subsystem. The issue stems from a double-lock acquisition pattern in `i3c_master_register()`, which acquires `i3cbus->lock` twice, potentially causing a deadlock condition. The vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUG [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42247

CVE-2024-42247 is a MEDIUM severity vulnerability (CVSS 5.5) in the WireGuard kernel module's allowedips component, specifically involving unaligned 64-bit memory accesses. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. The issue stems from improper memory alignment handling in the WireGuard allowedips implementation, which could lead to undefined behavior or p [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42244

A vulnerability in the Linux kernel's USB serial mos7840 driver can cause a system crash during resume operations. The issue stems from a change in the USB serial core that calls a generic resume implementation when the driver lacks one. For the mos7840 driver, which supports multiple read URBs, both port read URBs are submitted on resume for open ports, but the context pointer of the second URB remains s [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42236

CVE-2024-42236 describes an out-of-bounds (OOB) read/write vulnerability in the Linux kernel's USB gadget configfs subsystem, specifically within the `usb_string_copy()` function. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens ProductCERT issued advisory SSA-355557 addressing this CVE, which CISA subsequently republished as ICSA-25-226-07 on 2025-08-12 with updates [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42232

CVE-2024-42232 is a race condition vulnerability in libceph, the Ceph client library used within Siemens industrial networking products. The flaw exists in how delayed work is handled during monitor client shutdown (ceph_monc_stop()), creating a window where mon_fault() or finish_hunting() can requeue delayed work after cancel_delayed_work_sync() has already executed. This race can lead to use-after-free [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42229

A cryptographic key buffer zeroization vulnerability in Linux kernel crypto (aead,cipher) subsystems, affecting Siemens industrial network infrastructure products running SINEC OS. The flaw leaves key material in memory after cryptographic operations complete, potentially exposing sensitive key data to memory disclosure attacks. CISA and Siemens published coordinated advisories in August 2025, with subseq [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-42224

A logic error in the Marvell 88E6xxx Distributed Switch Architecture (DSA) driver for Linux could lead to incorrect handling of empty lists. The vulnerability stems from an improper check when determining if a list is empty, potentially causing unexpected behavior in network switch operations. Siemens has identified this as affecting certain industrial networking products running SINEC OS, though the spec [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42223

CVE-2024-42223 is a medium-severity integer overflow vulnerability in the Linux kernel's DVB frontend driver for the TDA10048 demodulator. The flaw occurs because `state->xtal_hz` can reach up to 16 MHz, and when multiplied by `pll_mfactor`, the result can overflow a 32-bit integer. This vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has identified this CVE [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-42161

CVE-2024-42161 is a HIGH-severity advisory published by CISA on 2025-03-11 for Siemens SIMATIC S7-1500 TM MFP - BIOS. The source corpus also identifies the underlying issue as a Linux kernel BPF_CORE_READ_BITFIELD uninitialized-value problem. CISA/Siemens state that no fix is currently available and recommend limiting the system to trusted software sources.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42154

CVE-2024-42154 is described in the supplied source corpus as a Linux kernel tcp_metrics input-validation issue that appears in Siemens advisory ICSA-25-072-03 / SSA-503939 for SIMATIC S7-1500 TM MFP - BIOS. The issue is that TCP_METRICS_ATTR_SADDR_IPV4 was not checked to ensure it was at least 4 bytes long, and the policy did not define an entry for that attribute; the advisory rates the issue CVSS v3.1 5 [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42153

A potential deadlock condition exists in the I2C PNX driver where `del_timer_sync()` is called within an interrupt service routine (ISR). This pattern can trigger kernel warnings and may lead to system instability or denial of service conditions in affected industrial control systems. The vulnerability stems from improper synchronization primitives usage in kernel-level I2C bus handling code.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42148

CVE-2024-42148 describes multiple UBSAN (Undefined Behavior Sanitizer) array-index-out-of-bounds issues in the bnx2x network driver. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. CISA's advisory ICSA-25-226-07, which was republished on 2026-02-25 based on Siemens ProductCERT advisory SSA-355557, identifies this CVE as affecting Siemens industrial networking products includ [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42145

A vulnerability in the Linux kernel's InfiniBand (IB) core subsystem allows an unbounded UMAD (User-space MAD) receive list to grow without limit, potentially leading to resource exhaustion. The issue stems from inadequate bounds checking on the receive queue, which could be exploited to cause denial of service through memory exhaustion. This vulnerability affects Siemens industrial networking products th [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42106

This CVE addresses an uninitialized memory vulnerability in the Linux kernel's inet_diag subsystem. The fix initializes the pad field in struct inet_diag_req_v2, which was previously left uninitialized. This vulnerability could potentially lead to information disclosure or other undefined behavior when the uninitialized padding bytes are accessed. The issue affects Siemens industrial networking products r [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-42105

A use-after-free vulnerability in the nilfs2 filesystem affects Siemens industrial networking products running SINEC OS. The vulnerability was initially listed in CISA advisory ICSA-25-226-07 published 2025-08-12, which was subsequently revised multiple times through 2026-02-25 to correct affected product listings and remove rejected CVEs. The source advisory explicitly marks impact as 'Misinformed' for t [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-42102

A vulnerability in the Linux kernel's memory management dirty throttling logic, where a reverted commit introduced multiplication overflow on 32-bit architectures when dirty thresholds exceed 32-bit limits. The issue affects Siemens industrial networking products running vulnerable kernel versions.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-42095

A vulnerability in the 8250_omap serial driver can trigger an erroneous timeout, potentially causing an interrupt storm. This condition may lead to system instability or denial of service on affected devices. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has assessed this CVE as not affecting their products, with the impact marked as 'Misinformed' in t [truncated]