These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A deadlock vulnerability in the Linux kernel's ASoC (ALSA System on Chip) rt5645 audio codec driver has been identified and resolved. The vulnerability exists in the `rt5645_jack_detect_work()` function, where improper locking behavior could cause a deadlock condition. This affects Siemens industrial networking products that incorporate the vulnerable kernel component, specifically the RUGGEDCOM RST2428P [truncated]
A divide-by-zero vulnerability in the Linux kernel's writeback code (mm/writeback) was resolved in kernel development. The flaw existed in the wb_dirty_limits() function. Siemens has assessed this CVE as **Misinformed** for affected industrial networking products (RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family) per CISA advisory ICSA-25 [truncated]
A double-free vulnerability in the Linux kernel's ext4 filesystem driver, specifically in extent handling code, has been identified and resolved. The flaw occurs due to incorrect tracking of moved_len during extent manipulation operations, which can lead to the same blocks being freed twice. This vulnerability affects Siemens industrial networking products that utilize the vulnerable Linux kernel version, [truncated]
A boundary check vulnerability in the Linux kernel's RM3100 magnetometer driver (iio: magnetometer: rm3100) was resolved by adding validation for values read from RM3100_REG_TMRC. The vulnerability involves insufficient boundary checking of register values that could lead to undefined behavior. Siemens has assessed this CVE as 'Misinformed' for affected industrial networking products including the RUGGEDC [truncated]
A vulnerability in the Linux kernel's nilfs2 filesystem could cause data corruption during dsync block recovery when small block sizes are used. The issue has been resolved in the kernel. Siemens has assessed this CVE as 'Misinformed' for its affected industrial networking products, indicating the vulnerability does not apply to these systems as initially reported.
A vulnerability in the Linux kernel's nilfs2 filesystem could cause a hang condition in the nilfs_lookup_dirty_data_buffers() function. This issue has been resolved in the upstream Linux kernel. Siemens has identified this CVE as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X family switches. The vulnerability was initially published on A [truncated]
CVE-2024-26688 is a NULL pointer dereference vulnerability in the Linux kernel's hugetlb filesystem (hugetlbs_fill_super). The vulnerability was resolved in the upstream Linux kernel. Siemens has assessed this CVE as 'Misinformed' for affected industrial networking products including the RUGGEDCOM RST2428P and SCALANCE X-family devices, indicating the vulnerability does not affect these products as initia [truncated]
A vulnerability in the Linux kernel's nilfs2 filesystem was resolved with a fix for a potential bug in the end_buffer_async_write function. The issue was addressed in the kernel source tree. Siemens has assessed this CVE as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X family devices. The vulnerability was initially published on August 1 [truncated]
This CVE addresses a vulnerability in the Linux kernel's stmmac (Synopsys DesignWare Ethernet MAC) driver, specifically within the XGMAC (10 Gigabit Ethernet MAC) implementation. The issue involves improper handling of DPP (Data Path Protection) safety errors for DMA channels. DPP is a safety mechanism designed to detect and handle errors in data transmission paths. When this safety error handling fails, [truncated]
A vulnerability in the Linux kernel's inet_recv_error() function was resolved by ensuring the socket family (sk->sk_family) is read only once. This change prevents potential race conditions or inconsistent state that could arise from multiple reads of the socket family field during error handling in network operations. The fix was incorporated into the Linux kernel and subsequently affects Siemens industr [truncated]
A vulnerability in the Linux kernel's PPP asynchronous driver (ppp_async) allowed the Maximum Receive Unit (MRU) to exceed safe bounds, potentially enabling memory corruption or denial of service conditions. The issue was resolved by limiting MRU to 64KB. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCA [truncated]
A vulnerability in the Linux kernel's netfilter nft_ct subsystem allowed improper handling of layer 3 and layer 4 protocol numbers in custom connection tracking expectations. The flaw was resolved by adding sanitization checks to validate these protocol numbers. Siemens has assessed this CVE as **Misinformed** for its affected industrial networking products, indicating the vulnerability does not apply to [truncated]
CVE-2024-26664 is an out-of-bounds memory access vulnerability in the Linux kernel's hwmon (coretemp) subsystem. The vulnerability was resolved in the Linux kernel, and Siemens has assessed its impact on affected industrial networking products. According to the CISA CSAF advisory ICSA-25-226-15, Siemens has categorized the impact as 'Misinformed' for affected products including the RUGGEDCOM RST2428P and [truncated]
CVE-2024-26663 is a vulnerability in the Linux kernel's Transparent Inter-Process Communication (TIPC) subsystem. The issue involves a missing validation check on bearer type before calling `tipc_udp_nl_bearer_add()`, which could lead to improper handling of network bearer configuration. The vulnerability was resolved by adding a check to validate the bearer type prior to the function call. This CVE was p [truncated]
A race condition vulnerability in the Linux kernel's tracing subsystem, specifically within the tracing_map implementation, has been identified and resolved. The issue involves insufficient memory visibility guarantees when inserting elements into tracing_map structures, which could lead to inconsistent or corrupted tracing data under concurrent access conditions. The vulnerability affects Siemens industr [truncated]
A vulnerability in the Linux kernel's Logical Link Control (LLC) protocol implementation, specifically in the llc_ui_sendmsg() function, has been resolved. The fix addresses a race condition where bonding network interface changes could cause instability or unexpected behavior during message transmission. The vulnerability was present in Siemens industrial networking products running affected Linux kernel [truncated]
CVE-2024-26635 is a Linux kernel vulnerability in the LLC (Logical Link Control) subsystem, specifically involving the removal of support for ETH_P_TR_802_2. The vulnerability was resolved by dropping support for this protocol identifier. The issue was published on August 12, 2025, with subsequent modifications through February 25, 2026. Siemens has identified this vulnerability as affecting certain indus [truncated]
This CVE addresses a vulnerability in the Linux kernel's Logical Link Control (LLC) protocol implementation. The fix involves calling sock_orphan() at socket release time to properly handle socket lifecycle management. The vulnerability was resolved in the Linux kernel, and Siemens has assessed the impact on their industrial networking products as 'Misinformed' per their CSAF advisory, indicating the vuln [truncated]
A vulnerability in the Linux kernel's Shared Memory Communications over Direct Memory Access (SMC-D) subsystem could allow illegal memory access during connection dump operations. The issue stems from improper handling of the rmb_desc (remote memory buffer descriptor) structure when dumping SMC-D connection state. Siemens has identified this vulnerability as affecting certain industrial networking product [truncated]
This CVE addresses a vulnerability in the Linux kernel's binder driver where epoll threads were not properly signaled when self-work became available. The issue has been resolved in the kernel. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. The vulnerability was initially pu [truncated]
A NULL pointer dereference vulnerability in the Texas Instruments OMAP USB2 PHY driver (phy-omap-usb2) within the Linux kernel, specifically affecting Session Request Protocol (SRP) functionality. The vulnerability was resolved in the Linux kernel with a fix for the NULL pointer dereference condition. Siemens has identified this CVE as applicable to certain industrial networking products running SINEC OS, [truncated]
A use-after-free (UAF) vulnerability in the Linux kernel's KVM ARM64 vGIC-ITS (Virtual Generic Interrupt Controller - Interrupt Translation Service) subsystem could allow a malicious guest VM to corrupt memory or escalate privileges. The flaw exists in the LPI (Locality-specific Peripheral Interrupt) translation cache implementation, where improper synchronization may lead to accessing freed memory. This [truncated]
A vulnerability in the Linux kernel's i2c i801 driver affecting block process call transactions has been identified in Siemens industrial networking products. The issue was resolved in the upstream Linux kernel. Siemens has assessed the impact as 'Misinformed' for affected products, indicating the vulnerability does not pose a practical security risk to the identified product lines. The advisory was initi [truncated]
A vulnerability in the Linux kernel's netfilter subsystem, specifically within the nft_set_rbtree module, has been identified and resolved. The issue involves improper garbage collection (GC) handling of end interval elements in the red-black tree data structure used for nftables sets. When garbage collection processes these end interval elements incorrectly, it can lead to use-after-free conditions or me [truncated]
CVE-2024-25741 is a medium-severity vulnerability in the Linux kernel's USB gadget printer driver (f_printer.c) affecting versions through 6.7.4. The flaw stems from improper handling of the usb_ep_queue function call in printer_write, which may allow attackers to cause denial of service or other unspecified impacts. Siemens has identified this vulnerability as affecting certain industrial networking prod [truncated]
A privilege escalation vulnerability in Siemens RUGGEDCOM APE1808 allows a local service account to elevate privileges due to excessively permissive sudo rules. The vulnerability has a CVSS 3.1 score of 7.0 (HIGH severity). An attacker who can execute arbitrary commands as the affected service account could potentially gain administrative access to the system. The vulnerability was published on August 12, [truncated]
An OS command injection vulnerability exists in the update functionality of Siemens RUGGEDCOM APE1808, which runs Nozomi Networks Guardian and CMC software. The flaw stems from an improper signature validation check on update packages. While updates are cryptographically signed and signatures are validated before installation, the validation logic is flawed, allowing an authenticated administrator to uplo [truncated]
A null pointer dereference vulnerability exists in the Linux kernel's hugetlbfs (HugeTLB pages) functionality, specifically within the hugetlbfs_fill_super function. This flaw may allow a local user to crash the system or potentially escalate privileges. The vulnerability affects Siemens industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA [truncated]
A use-after-free vulnerability exists in the Linux kernel's IGMP (Internet Group Management Protocol) implementation, specifically in the `igmp_start_timer` function within `net/ipv4/igmp.c`. The flaw occurs when processing IGMP query packets, where improper reference counting can lead to a use-after-free condition. This vulnerability allows a local attacker to trigger a kernel information leak by observi [truncated]
A use-after-free vulnerability in the Linux kernel's netfilter subsystem affects Siemens industrial networking products. The flaw occurs when a catchall element in the pipapo set is garbage-collected during set removal, causing double deactivation and potential use-after-free on NFT_CHAIN or NFT_OBJECT structures. A local attacker with CAP_NET_ADMIN capability could exploit this to escalate privileges. Th [truncated]