ICSA-25-226-07: Siemens Third-Party Components in SINEC OS
CISA advisory · released 2025-08-12
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 4, 2026-02-25 (final)
CISA's summary
Summary: SINEC OS before V3.2 contains third-party components with multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | RUGGEDCOM RST2428P (6GK6242-6PA00) | vers:intdot/<3.2 |
| Siemens | RUGGEDCOM RST2428P (6GK6242-6PA00) | vers:all/* |
| Siemens | SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family | vers:all/* |
| Siemens | SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family | vers:intdot/<3.2 |
| Siemens | SCALANCE XCM-/XRM-/XCH-/XRH-300 family | vers:intdot/<3.2 |
| Siemens | SCALANCE XCM-/XRM-/XCH-/XRH-300 family | vers:all/* |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2021-47316 — CVE-2021-47316 · CWE-20
nfsd: NULL dereference in nfs3svc_encode_getaclres.
- CVE-2022-48666 — CVE-2022-48666 · CWE-416
scsi: core: use-after-free vulnerability.
- CVE-2022-48827 — CVE-2022-48827 · CWE-125
NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag.
- CVE-2022-48828 — CVE-2022-48828 · CWE-20
NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients.
- CVE-2022-48829 — CVE-2022-48829 · CWE-253
NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption.
- CVE-2022-49034 — CVE-2022-49034 · CWE-20
sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo.
- CVE-2023-4039 — CVE-2023-4039 · CWE-693
A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only applies to C99-style dynamically-sized local variables or those created using alloca(). The stack-protector operates as intended for statically-sized local variables. The default behavior when the stack-protector detects an overflow is to terminate your application, resulting in controlled loss of availability. An attacker who can exploit a buffer overflow without triggering the stack-protector might be able to change program flow control to cause an uncontrolled loss of availability or to go further and affect confidentiality or integrity.
- CVE-2023-52887 — CVE-2023-52887 · CWE-20
net: can: j1939: vulnerability related to error handling for closely received RTS messages in xtp_rx_rts_session_new, which is addressed by replacing less informative backtraces with a new method that provides clearer error messages and allows for early termination of problematic sessions.
- CVE-2023-52918 — CVE-2023-52918 · CWE-20
In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() return cx23885_vdev_init() can return a NULL pointer, but that pointer is used in the next line without a check. Add a NULL pointer check and go to the error unwind if it is NULL.
- CVE-2024-6197 — CVE-2024-6197 · CWE-590
libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.
- CVE-2024-6874 — CVE-2024-6874 · CWE-126
libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer when built to use the *macidn* IDN backend. The conversion function then fills up the provided buffer exactly - but does not null terminate the string. This flaw can lead to stack contents accidently getting returned as part of the converted string.
- CVE-2024-7264 — CVE-2024-7264 · CWE-125
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
- CVE-2024-8176 — CVE-2024-8176 · CWE-674
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
- CVE-2024-9681 — CVE-2024-9681 · CWE-697
When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's HSTS cache. The result of a triggered bug is that HTTP accesses to `example.com` get converted to HTTPS for a different period of time than what was asked for by the origin server. If `example.com` for example stops supporting HTTPS at its expiry time, curl might then fail to access `http://example.com` until the (wrongly set) timeout expires. This bug can also expire the parent's entry *earlier*, thus making curl inadvertently switch back to insecure HTTP earlier than otherwise intended.
- CVE-2024-36484 — CVE-2024-36484 · CWE-99
In the Linux kernel, the following vulnerability has been resolved: net: relax socket state check at accept time.
- CVE-2024-36894 — CVE-2024-36894 · CWE-362
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
- CVE-2024-36901 — CVE-2024-36901 · CWE-476
ipv6: prevent NULL dereference in ip6_output() According to syzbot, there is a chance that ip6_dst_idev() returns NULL in ip6_output().
- CVE-2024-36938 — CVE-2024-36938 · CWE-20
Denial of Service Vulnerability in the Linux Kernel: bpf, skmsg: Fix NULL pointer dereference in sk_psock_skb_ingress_enqueue Fix NULL pointer data-races in sk_psock_skb_ingress_enqueue() which syzbot reported.
- CVE-2024-36974 — CVE-2024-36974 · CWE-20
net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP. If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate it, or userspace can inject arbitrary data to the kernel, the second time taprio_change() is called. First call (with valid attributes) sets dev->num_tc to a non zero value. Second call (with arbitrary mqprio attributes) returns early from taprio_parse_mqprio_opt() and bad things can happen.
- CVE-2024-36978 — CVE-2024-36978 · CWE-20
net: sched: sch_multiq: possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be used in kmalloc. Otherwise, an out-of-bounds write will occur.
- CVE-2024-37078 — CVE-2024-37078 · CWE-20
nilfs2: kernel vulnerability due to lack of writeback flag waiting. When the log writer starts a writeback for segment summary blocks or a super root block that use the backing devices page cache, it does not wait for the ongoing folio/page writeback, resulting in an inconsistent writeback state.
- CVE-2024-38586 — CVE-2024-38586 · CWE-20
r8169: possible ring buffer corruption on fragmented Tx packets. Vulnerability on the RTL8125b when transmitting small fragmented packets, whereby invalid entries were inserted into the transmit ring buffer, subsequently leading to calls to dma_unmap_single() with a null address. This was caused by rtl8169_start_xmit() not noticing changes to nr_frags which may occur when small packets are padded (to work around hardware quirks) in rtl8169_tso_csum_v2().
- CVE-2024-38619 — CVE-2024-38619 · CWE-20
usb-storage: alauda: Check whether the media is initialized. The member "uzonesize" of struct alauda_info will remain 0 if alauda_init_media() fails, potentially causing divide errors in alauda_read_data() and alauda_write_lba().
- CVE-2024-39468 — CVE-2024-39468 · CWE-20
smb: client: Deadlock in smb2_find_smb_tcon().
- CVE-2024-39469 — CVE-2024-39469 · CWE-1050
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() when a directory folio/page read fails is incorrect, as in the old ext2 implementation, and if the folio/page cannot be read or nilfs_check_folio() fails, it will falsely determine the directory as empty and corrupt the file system. In addition, since nilfs_empty_dir() does not immediately return on a failed folio/page read, but continues to loop, this can cause a long loop with I/O if i_size of the directory's inode is also corrupted, causing the log writer thread to wait and hang, as reported by syzbot. Fix these issues by making nilfs_empty_dir() immediately return a false value (0) if it fails to get a directory folio/page.
- CVE-2024-39482 — CVE-2024-39482 · CWE-20
bcache: Variable length array abuse in btree_iter.
- CVE-2024-39484 — CVE-2024-39484 · CWE-770
mmc: davinci: Vulnerability from resource leaks. Using __exit for the remove function results in the remove callback being discarded with CONFIG_MMC_DAVINCI=y. When such a device gets unbound (e.g. using sysfs or hotplug), the driver is just removed without the cleanup being performed.
- CVE-2024-39487 — CVE-2024-39487 · CWE-125
In the Linux kernel, the following vulnerability has been resolved: bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set().
- CVE-2024-39495 — CVE-2024-39495 · CWE-416
greybus: use-after-free vulnerability in gb_interface_release due to race condition.
- CVE-2024-39499 — CVE-2024-39499 · CWE-119
vmci: speculation leaks by sanitizing event in event_deliver(). event_msg is controlled by user-space, event_msg->event_data.event is passed to event_deliver() and used as an index without sanitization, leading to information leaks.
- CVE-2024-39502 — CVE-2024-39502 · CWE-416
ionic: use after netif_napi_del(). When queues are started, netif_napi_add() and napi_enable() are called. If there are 4 queues and only 3 queues are used for the current configuration, only 3 queues' napi should be registered and enabled. The ionic_qcq_enable() checks whether the .poll pointer is not NULL for enabling only the using queue' napi. Unused queues' napi will not be registered by netif_napi_add(), so the .poll pointer indicates NULL. But it couldn't distinguish whether the napi was unregistered or not because netif_napi_del() doesn't reset the .poll pointer to NULL. So, ionic_qcq_enable() calls napi_enable() for the queue, which was unregistered by netif_napi_del().
- CVE-2024-39503 — CVE-2024-39503 · CWE-416
netfilter: ipset: race between namespace cleanup and gc in the list:set type. The namespace cleanup can destroy the list:set type of sets while the gc of the set type is waiting to run in rcu cleanup. The latter uses data from the destroyed set which thus leads use after free.
- CVE-2024-39505 — CVE-2024-39505 · CWE-20
drm/komeda: check for error-valued pointer. komeda_pipeline_get_state() may return an error-valued pointer, thus check the pointer for negative or null value before dereferencing.
- CVE-2024-39506 — CVE-2024-39506 · CWE-476
liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet. In lio_vf_rep_copy_packet() pg_info->page is compared to a NULL value, but then it is unconditionally passed to skb_add_rx_frag(), which could lead to null pointer dereference.
- CVE-2024-39509 — CVE-2024-39509 · CWE-20
HID: core: remove unnecessary WARN_ON() in implement(). There is a warning in a call to implement() when trying to write a value into a field of smaller size in an output report. Since implement() already has a warn message printed out with the help of hid_warn() and value in question gets trimmed with: ... value &= m; ... WARN_ON may be considered superfluous.
- CVE-2024-40901 — CVE-2024-40901 · CWE-125
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory.
- CVE-2024-40902 — CVE-2024-40902 · CWE-120
jfs: xattr: buffer overflow for invalid xattr. When an xattr size is not what is expected, it is printed out to the kernel log in hex format as a form of debugging. But when that xattr size is bigger than the expected size, printing it out can cause an access off the end of the buffer.
- CVE-2024-40904 — CVE-2024-40904 · CWE-20
USB: class: cdc-wdm: CPU lockup caused by excessive log messages.
- CVE-2024-40905 — CVE-2024-40905 · CWE-20
ipv6: possible race in __fib6_drop_pcpu_from().
- CVE-2024-40912 — CVE-2024-40912 · CWE-20
wifi: mac80211: deadlock in ieee80211_sta_ps_deliver_wakeup().
- CVE-2024-40916 — CVE-2024-40916 · CWE-20
drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found When reading EDID fails and driver reports no modes available, the DRM core adds an artificial 1024x786 mode to the connector.
- CVE-2024-40929 — CVE-2024-40929 · CWE-20
wifi: iwlwifi: mvm: check n_ssids before accessing the ssids.In some versions of cfg80211, the ssids poinet might be a valid one even though n_ssids is 0. Accessing the pointer in this case will cuase an out-of-bound access.
- CVE-2024-40931 — CVE-2024-40931 · CWE-20
mptcp: ensure snd_una is properly initialized on connect.
- CVE-2024-40932 — CVE-2024-40932 · CWE-20
drm/exynos/vidi: memory leak in .get_modes().
- CVE-2024-40934 — CVE-2024-40934 · CWE-404
HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode() Fix a memory leak on logi_dj_recv_send_report() error path.
- CVE-2024-40941 — CVE-2024-40941 · CWE-125
wifi: iwlwifi: mvm: don't read past the mfuart notifcation. In case the firmware sends a notification that claims it has more data than it has, it will read past that was allocated for the notification.
- CVE-2024-40942 — CVE-2024-40942 · CWE-402
wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects The hwmp code use objects of type mesh_preq_queue, added to a list in ieee80211_if_mesh, to keep track of mpath we need to resolve. If the mpath gets deleted, ex mesh interface is removed, the entries in that list will never get cleaned.
- CVE-2024-40943 — CVE-2024-40943 · CWE-362
ocfs2: fix races between hole punching and AIO+DIO.
- CVE-2024-40945 — CVE-2024-40945 · CWE-393
iommu: Return right value in iommu_sva_bind_device() iommu_sva_bind_device() should return either a sva bond handle or an ERR_PTR value in error cases. Existing drivers (idxd and uacce) only check the return value with IS_ERR(). This could potentially lead to a kernel NULL pointer dereference issue if the function returns NULL instead of an error pointer. In reality, this doesn't cause any problems because iommu_sva_bind_device() only returns NULL when the kernel is not configured with CONFIG_IOMMU_SVA.
- CVE-2024-40947 — CVE-2024-40947 · CWE-20
ima: Avoid blocking in RCU read-side critical section, a panic happens in ima_match_policy.
- CVE-2024-40958 — CVE-2024-40958 · CWE-416
netns: Make get_net_ns() handle zero refcount net Syzkaller hit a warning: refcount_t: addition on 0; use-after-free.
- CVE-2024-40959 — CVE-2024-40959 · CWE-476
In the Linux kernel, the following vulnerability has been resolved: xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr().
- CVE-2024-40960 — CVE-2024-40960 · CWE-476
ipv6: prevent possible NULL dereference in rt6_probe() syzbot caught a NULL dereference in rt6_probe() [1] Bail out if __in6_dev_get() returns NULL.
- CVE-2024-40961 — CVE-2024-40961 · CWE-476
ipv6: prevent possible NULL deref in fib6_nh_init() syzbot reminds us that in6_dev_get() can return NULL.
- CVE-2024-40963 — CVE-2024-40963 · CWE-20
mips: bmips: BCM6358: Some device have CBR address set to 0 causing kernel panic when arch_sync_dma_for_cpu_all is called.
- CVE-2024-40968 — CVE-2024-40968 · CWE-20
MIPS:The standard PCIe configuration read-write interface is used to access the configuration space of the peripheral PCIe devices of the mips processor after the PCIe link surprise down, it can generate kernel panic caused by "Data bus error".
- CVE-2024-40971 — CVE-2024-40971 · CWE-20
f2fs: remove clear SB_INLINECRYPT flag in default_options In f2fs_remount, SB_INLINECRYPT flag will be clear and re-set. If create new file or open file during this gap, these files will not use inlinecrypt. Worse case, it may lead to data corruption if wrappedkey_v0 is enable.
- CVE-2024-40974 — CVE-2024-40974 · CWE-20
powerpc/pseries: stack corruption at runtime when plpar_hcall9() stores results past the end of the array.
- CVE-2024-40976 — CVE-2024-40976 · CWE-20
drm/lima: There is a race condition in which a rendering job might take just long enough to trigger the drm sched job timeout handler but also still complete before the hard reset is done by the timeout handler. This runs into race conditions not expected by the timeout handler. In some very specific cases it currently may result in a refcount imbalance on lima_pm_idle, with a stack dump.
- CVE-2024-40978 — CVE-2024-40978 · CWE-20
scsi: qedi: crash while reading debugfs attribute. The qedi_dbg_do_not_recover_cmd_read() function invokes sprintf() directly on a __user pointer, which results into the crash.
- CVE-2024-40980 — CVE-2024-40980 · CWE-20
drop_monitor: replace spin_lock by raw_spin_lock trace_drop_common() is called with preemption disabled, and it acquires a spin_lock. This is problematic for RT kernels because spin_locks are sleeping locks in this configuration, which causes the following splat.
- CVE-2024-40981 — CVE-2024-40981 · CWE-20
batman-adv: empty buckets in batadv_purge_orig_ref() are pointing to soft lockups in batadv_purge_orig_ref().
- CVE-2024-40983 — CVE-2024-40983 · CWE-20
tipc: possible crash before doing decryption.
- CVE-2024-40984 — CVE-2024-40984 · CWE-476
ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
- CVE-2024-40987 — CVE-2024-40987 · CWE-20
drm/amdgpu: UBSAN warning in kv_dpm.c.
- CVE-2024-40988 — CVE-2024-40988 · CWE-20
drm/radeon: UBSAN warning in kv_dpm.c.
- CVE-2024-40990 — CVE-2024-40990 · CWE-20
ptp: integer overflow in max_vclocks_store.
- CVE-2024-40995 — CVE-2024-40995 · CWE-20
net/sched: act_api: possible infinite loop in tcf_idr_check_alloc().
- CVE-2024-41000 — CVE-2024-41000 · CWE-190
block/ioctl: prefer different overflow check Running syzkaller with the newly reintroduced signed integer overflow sanitizer.
- CVE-2024-41004 — CVE-2024-41004 · CWE-20
tracing: Build event generation tests only as modules The kprobes and synth event generation test modules add events and lock (get a reference) those event file reference in module init function, and unlock and delete it in module exit function. This is because those are designed for playing as modules. If we make those modules as built-in, those events are left locked in the kernel, and never be removed.
- CVE-2024-41005 — CVE-2024-41005 · CWE-362
netpoll: race condition in netpoll_owner_active KCSAN detected a race condition in netpoll.
- CVE-2024-41006 — CVE-2024-41006 · CWE-404
netrom: a memory leak in nr_heartbeat_expiry().
- CVE-2024-41007 — CVE-2024-41007 · CWE-99
tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT.
- CVE-2024-41009 — CVE-2024-41009 · CWE-770
bpf: Fix overrunning reservations in ringbuf.
- CVE-2024-41012 — CVE-2024-41012 · CWE-416
filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait().
- CVE-2024-41015 — CVE-2024-41015 · CWE-20
ocfs2: add bounds checking to ocfs2_check_dir_entry(). This adds sanity checks for ocfs2_dir_entry to make sure all members of ocfs2_dir_entry don't stray beyond valid memory region.
- CVE-2024-41017 — CVE-2024-41017 · CWE-20
jfs: vulnerability involves the risk of accessing memory beyond the end of ealist, which can lead to undefined behavior or crashes.
- CVE-2024-41020 — CVE-2024-41020 · CWE-20
filelock: race condition vulnerability between fcntl and close operations, which can lead to issues in the recovery compatibility path.
- CVE-2024-41022 — CVE-2024-41022 · CWE-20
drm/amdgpu: vulnerability involves a signedness problem in sdma_v4_0_process_trap_irq(), which can lead to incorrect handling of values and potential errors.
- CVE-2024-41034 — CVE-2024-41034 · CWE-20
nilfs2: kernel bug on rename operation of broken directory.
- CVE-2024-41035 — CVE-2024-41035 · CWE-20
USB: core: duplicate endpoint bug.
- CVE-2024-41040 — CVE-2024-41040 · CWE-20
net/sched: UAF when resolving a clash.
- CVE-2024-41041 — CVE-2024-41041 · CWE-20
udp: small race window.
- CVE-2024-41044 — CVE-2024-41044 · CWE-20
ppp: claimed-as-LCP but actually malformed packets.
- CVE-2024-41046 — CVE-2024-41046 · CWE-415
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times.
- CVE-2024-41049 — CVE-2024-41049 · CWE-416
In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen.
- CVE-2024-41055 — CVE-2024-41055 · CWE-476
In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem: fix race in accessing memory_section->usage") changed pfn_section_valid() to add a READ_ONCE() call around "ms->usage" to fix a race with section_deactivate() where ms->usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it.
- CVE-2024-41059 — CVE-2024-41059 · CWE-20
hfsplus: uninit-value in copy_name.
- CVE-2024-41063 — CVE-2024-41063 · CWE-20
Bluetooth: hci_core: deadlock at destroy_workqueue().
- CVE-2024-41064 — CVE-2024-41064 · CWE-20
powerpc/eeh: possible crash when edev->pdev changes.
- CVE-2024-41065 — CVE-2024-41065 · CWE-20
powerpc/pseries: Reading the dispatch trace log from /sys/kernel/debug/powerpc/dtl/cpu-* results in a BUG().
- CVE-2024-41068 — CVE-2024-41068 · CWE-20
s390/sclp: sclp_init() failure.
- CVE-2024-41070 — CVE-2024-41070 · CWE-20
KVM: PPC: Book3S HV: UAF in kvm_spapr_tce_attach_iommu_group().
- CVE-2024-41072 — CVE-2024-41072 · CWE-20
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: wext: add extra SIOCSIWSCAN data check In 'cfg80211_wext_siwscan()', add extra check whether number of channels passed via 'ioctl(sock, SIOCSIWSCAN, ...)' doesn't exceed IW_MAX_FREQUENCIES and reject invalid request with -EINVAL otherwise.
- CVE-2024-41077 — CVE-2024-41077 · CWE-20
null_blk: validation error on block size.
- CVE-2024-41078 — CVE-2024-41078 · CWE-20
btrfs: qgroup: quota root leak after quota disable failure.
- CVE-2024-41081 — CVE-2024-41081 · CWE-20
ila: block BH in ila_output().
- CVE-2024-41087 — CVE-2024-41087 · CWE-20
ata: libata-core: double free on error.
- CVE-2024-41089 — CVE-2024-41089 · CWE-20
drm/nouveau/dispnv04: null pointer dereference in nv17_tv_get_hd_modes.
- CVE-2024-41090 — CVE-2024-41090 · CWE-20
tap: add missing verification for short frame. Missing to check against the validity of the frame length in the tap_get_user_xdp() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tap_get_user_xdp()-->skb_set_network_header() may assume the size is more than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata.
- CVE-2024-41091 — CVE-2024-41091 · CWE-20
tun: add missing verification for short frame. Missing to check against the validity of the frame length in the tun_xdp_one() path could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tun_xdp_one-->eth_type_trans() may access the Ethernet header although it can be less than ETH_HLEN. Once transmitted, this could either causeout-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata.
- CVE-2024-41092 — CVE-2024-41092 · CWE-20
drm/i915/gt: potential UAF by revoke of fence registers.
- CVE-2024-41095 — CVE-2024-41095 · CWE-20
drm/nouveau/dispnv04: null pointer dereference in nv17_tv_get_ld_modes.
- CVE-2024-41097 — CVE-2024-41097 · CWE-20
usb: atm: cxacru: incomplete endpoint checking in cxacru_bind().
- CVE-2024-42076 — CVE-2024-42076 · CWE-20
net: can: j1939: unused data in j1939_send_one().
- CVE-2024-42077 — CVE-2024-42077 · CWE-20
ocfs2: DIO failure due to insufficient transaction credits.
- CVE-2024-42082 — CVE-2024-42082 · CWE-770
xdp: unused WARN() in __xdp_reg_mem_model().
- CVE-2024-42084 — CVE-2024-42084 · CWE-20
ftruncate: passing a negative length accidentally succeeds in truncating to file size between 2GiB and 4GiB.
- CVE-2024-42086 — CVE-2024-42086 · CWE-20
iio: chemical: bme680: overflows in compensate() functions.
- CVE-2024-42087 — CVE-2024-42087 · CWE-20
drm/panel: ilitek-ili9881c: warning with GPIO controllers.
- CVE-2024-42092 — CVE-2024-42092 · CWE-20
gpio: davinci: There can be out of chips->irqs array boundaries access in davinci_gpio_probe().
- CVE-2024-42093 — CVE-2024-42093 · CWE-20
net/dpaa2: explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack can cause potential stack overflow.
- CVE-2024-42094 — CVE-2024-42094 · CWE-20
net/iucv: explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack can cause potential stack overflow.
- CVE-2024-42095 — CVE-2024-42095 · CWE-20
serial: 8250_omap: Erroneous timeout can be triggered, and it may lead to storm of interrupts.
- CVE-2024-42101 — CVE-2024-42101 · CWE-20
drm/nouveau: null pointer dereference in nouveau_connector_get_modes.
- CVE-2024-42105 — CVE-2024-42105 · CWE-20
nilfs2: use-after-free.
- CVE-2024-42145 — CVE-2024-42145 · CWE-20
IB/core: an unbounded UMAD receive list, poses a risk of uncontrolled growth.
- CVE-2024-42148 — CVE-2024-42148 · CWE-20
bnx2x: multiple UBSAN array-index-out-of-bounds.
- CVE-2024-42152 — CVE-2024-42152 · CWE-20
nvmet: possible leak when destroy a ctrl during qp establishment.
- CVE-2024-42153 — CVE-2024-42153 · CWE-20
i2c: pnx: potential deadlock warning from del_timer_sync() call in isr.
- CVE-2024-42154 — CVE-2024-42154 · CWE-805
In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least 4 bytes long, and the policy doesn't have an entry for this attribute at all (neither does it for IPv6 but v6 is manually validated).
- CVE-2024-42161 — CVE-2024-42161 · CWE-457
In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD.
- CVE-2024-42223 — CVE-2024-42223 · CWE-20
media: dvb-frontends: tda10048: integer overflow state->xtal_hz can be up to 16M, so it can overflow a 32 bit integer when multiplied by pll_mfactor.
- CVE-2024-42224 — CVE-2024-42224 · CWE-20
net: dsa: mv88e6xxx: wrong check on empty list.
- CVE-2024-42229 — CVE-2024-42229 · CWE-20
crypto: aead,cipher - key buffer after use not zeroized.
- CVE-2024-42232 — CVE-2024-42232 · CWE-362
libceph: fix race between delayed_work() and ceph_monc_stop() The way the delayed work is handled in ceph_monc_stop() is prone to races with mon_fault() and possibly also finish_hunting(). Both of these can requeue the delayed work which wouldn't be canceled by any of the following code in case that happens after cancel_delayed_work_sync() runs -- __close_session() doesn't mess with the delayed work in order to avoid interfering with the hunting interval logic. This part was missed in(libceph: behave in mon_fault() if cur_mon < ") and use-after-free can still ensue on monc and objects that hang off of it, with monc-> auth and monc->monmap being particularly susceptible to quickly being reused.
- CVE-2024-42236 — CVE-2024-42236 · CWE-20
usb: gadget: configfs: OOB read/write in usb_string_copy().
- CVE-2024-42244 — CVE-2024-42244 · CWE-99
USB: serial: mos7840: fix crash on resume Since("USB: serial: use generic method if no alternative is provided in usb serial layer"), USB serial core calls the generic resume implementation when the driver has not provided one. This can trigger a crash on resume with mos7840 since support for multiple read URBs was added back in 2011. Specifically, both port read URBs are now submitted on resume for open ports, but the context pointer of the second URB is left set to the core rather than mos7840 port structure.
- CVE-2024-42247 — CVE-2024-42247 · CWE-20
wireguard: allowedips: unaligned 64-bit memory accesses.
- CVE-2024-43098 — CVE-2024-43098 · CWE-20
i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock. A deadlock may happen since the i3c_master_register() acquires i3cbus->lock twice.
- CVE-2024-43861 — CVE-2024-43861 · CWE-20
net: usb: qmi_wwan: memory leak for not ip packets.
- CVE-2024-43867 — CVE-2024-43867 · CWE-20
drm/nouveau: prime: refcount underflow.
- CVE-2024-43871 — CVE-2024-43871 · CWE-416
In the Linux kernel, the following vulnerability has been resolved: devres: Fix memory leakage caused by driver API devm_free_percpu() It will cause memory leakage when use driver API devm_free_percpu() to free memory allocated by devm_alloc_percpu(), fixed by using devres_release() instead of devres_destroy() within devm_free_percpu().
- CVE-2024-43879 — CVE-2024-43879 · CWE-20
wifi: cfg80211: Currently NL80211_RATE_INFO_HE_RU_ALLOC_2x996 is not handled in cfg80211_calculate_bitrate_he(), leading to warning.
- CVE-2024-43880 — CVE-2024-43880 · CWE-20
mlxsw: spectrum_acl_erp: object nesting warning.
- CVE-2024-43882 — CVE-2024-43882 · CWE-20
exec: the execution may gain unintended privileges.
- CVE-2024-43883 — CVE-2024-43883 · CWE-20
usb: vhci-hcd: vulnerability due to the vhci-hcd driver dropping references before new ones were gained, potentially leading to the use of stale pointers.
- CVE-2024-43889 — CVE-2024-43889 · CWE-20
padata: vulnerability due to a possible divide-by-zero error in padata_mt_helper() during bootup, caused by an uninitialized chunk_size being zero.
- CVE-2024-43890 — CVE-2024-43890 · CWE-20
tracing: vulnerability due to an overflow in get_free_elt(), which could lead to infinite loops and CPU hangs when the tracing map becomes full.
- CVE-2024-43893 — CVE-2024-43893 · CWE-20
serial: core: vulnerability due to a missing check for uartclk being zero, leading to a potential divide-by-zero error when calling ioctl TIOCSSERIAL with an invalid baud_base.
- CVE-2024-43894 — CVE-2024-43894 · CWE-20
drm/client: vulnerability due to a potential null pointer dereference in drm_client_modeset_probe() when drm_mode_duplicate() fails, which was fixed by adding a check.
- CVE-2024-43907 — CVE-2024-43907 · CWE-20
drm/amdgpu/pm: null pointer dereference in apply_state_adjust_rules.
- CVE-2024-43908 — CVE-2024-43908 · CWE-20
drm/amdgpu: null pointer dereference in ras_manager.
- CVE-2024-43914 — CVE-2024-43914 · CWE-20
md/raid5: BUG_ON() while continue reshape after reassembling.
- CVE-2024-44935 — CVE-2024-44935 · CWE-476
sctp: Fix null-ptr-deref in reuseport_add_sock(). A Null Pointer Dereference in reuseport_add_sock() while accessing sk2->sk_reuseport_cb . The repro first creates a listener with SO_REUSEPORT. Then, it creates another listener on the same port and concurrently closes the first listener. The second listen() calls reuseport_add_sock() with the first listener as sk2, where sk2->sk_reuseport_cb is not expected to be cleared concurrently, but the close() does clear it by reuseport_detach_sock().
- CVE-2024-44944 — CVE-2024-44944 · CWE-401
In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calculate expect ID Delete expectation path is missing a call to the nf_expect_get_id() helper function to calculate the expectation ID, otherwise LSB of the expectation object address is leaked to userspace.
- CVE-2024-44949 — CVE-2024-44949 · CWE-20
parisc: fix a possible DMA corruption ARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be possible that two unrelated 16-byte allocations share a cache line. If one of these allocations is written using DMA and the other is written using cached write, the value that was written with DMA may be corrupted.
- CVE-2024-44954 — CVE-2024-44954 · CWE-20
ALSA: line6: vulnerability involved racy access to the midibuf in the ALSA line6 driver, which has been fixed by using a spinlock to prevent concurrent access issues.
- CVE-2024-44960 — CVE-2024-44960 · CWE-20
usb: gadget: core: Check for unset descriptor. It needs to be reassured that the descriptor has been set before looking at maxpacket. This fixes a null pointer panic in this case. This may happen if the gadget doesn't properly set up the endpoint for the current speed, or the gadget descriptors are malformed and the descriptor for the speed/endpoint are not found. No current gadget driver is known to have this problem, but this may cause a hard-to-find bug during development of new gadgets.
- CVE-2024-44965 — CVE-2024-44965 · CWE-229
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix pti_clone_pgtable() alignment assumption Guenter reported dodgy crashes on an i386-nosmp build using GCC-11 that had the form of endless traps until entry stack exhaust and then #DF from the stack guard. It turned out that pti_clone_pgtable() had alignment assumptions on the start address, notably it hard assumes start is PMD aligned. This is true on x86_64, but very much not true on i386. These assumptions can cause the end condition to malfunction, leading to a 'short' clone. Guess what happens when the user mapping has a short copy of the entry text? Use the correct increment form for addr to avoid alignment assumptions.
- CVE-2024-44969 — CVE-2024-44969 · CWE-20
s390/sclp: vulnerability could lead to data corruption if a Store Data operation is interrupted and the halt attempt fails, which was resolved by preventing the release of data buffers in such cases.
- CVE-2024-44971 — CVE-2024-44971 · CWE-401
net: dsa: bcm_sf2: vulnerability caused a memory leak by not decrementing the reference count after finding and removing PHY devices, which has been fixed by adding a call to phy_device_free() to balance the reference count.
- CVE-2024-44987 — CVE-2024-44987 · CWE-416
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb().
- CVE-2024-44988 — CVE-2024-44988 · CWE-20
net: dsa: mv88e6xxx: vulnerability caused an out-of-bound access in the mv88e6xxx driver due to an ATU violation causing the SPID to exceed DSA_MAX_PORTS, which was resolved by ensuring the SPID stays within the valid range.
- CVE-2024-44989 — CVE-2024-44989 · CWE-476
In the Linux kernel, the following vulnerability has been resolved: bonding: fix xfrm real_dev null pointer dereference.
- CVE-2024-44990 — CVE-2024-44990 · CWE-476
In the Linux kernel, the following vulnerability has been resolved: bonding: fix null pointer deref in bond_ipsec_offload_ok We must check if there is an active slave before dereferencing the pointer.
- CVE-2024-44995 — CVE-2024-44995 · CWE-20
net: hns3: a deadlock problem when config TC during resetting.
- CVE-2024-44998 — CVE-2024-44998 · CWE-20
atm: idt77252: use after free in dequeue_rx().
- CVE-2024-44999 — CVE-2024-44999 · CWE-20
gtp: missing network headers in gtp_dev_xmit().
- CVE-2024-45003 — CVE-2024-45003 · CWE-20
vfs: Some filesystems(eg. ext4 with ea_inode feature, ubifs with xattr) may do inode lookup in the inode evicting callback function, if the inode lookup is operated under the inode lru traversing context, deadlock problems may happen.
- CVE-2024-45006 — CVE-2024-45006 · CWE-20
xhci: Panther point NULL pointer deref at full-speed re-enumeration.
- CVE-2024-45008 — CVE-2024-45008 · CWE-20
Input: missing limit on max slots results in too large allocation at input_mt_init_slots().
- CVE-2024-45021 — CVE-2024-45021 · CWE-20
memcg_write_event_control(): a user-triggerable oops.
- CVE-2024-45025 — CVE-2024-45025 · CWE-20
bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps.
- CVE-2024-46673 — CVE-2024-46673 · CWE-415
scsi: aacraid: Fix double-free on probe failure. aac_probe_one() calls hardware-specific init functions through the aac_driver_ident::init pointer, all of which eventually call down to aac_init_adapter(). If aac_init_adapter() fails after allocating memory for aac_dev::queues, it frees the memory but does not clear that member. After the hardware-specific init function returns an error, aac_probe_one() goes down an error path that frees the memory pointed to by aac_dev::queues, resulting in a double-free.
- CVE-2024-46674 — CVE-2024-46674 · CWE-416
usb: dwc3: st: fix probed platform device ref count on probe error path. The probe function never performs any paltform device allocation, thus error path "undo_platform_dev_alloc" is entirely bogus. It drops the reference count from the platform device being probed. If error path is triggered, this will lead to unbalanced device reference counts and premature release of device resources, thus possible use-after-free when releasing remaining devm-managed resources.
- CVE-2024-46675 — CVE-2024-46675 · CWE-20
usb: dwc3: core: A vulnerability where the USB core could access an invalid event buffer address during runtime suspend, potentially causing SMMU faults and other memory issues in Exynos platforms.
- CVE-2024-46676 — CVE-2024-46676 · CWE-20
nfc: pn533: Add poll mod list filling check. In case of im_protocols value is 1 and tm_protocols value is 0 this combination successfully passes the check 'if (!im_protocols && !tm_protocols)' in the nfc_start_poll(). But then after pn533_poll_create_mod_list() call in pn533_start_poll() poll mod list will remain empty and dev->poll_mod_count will remain 0 which lead to division by zero.
- CVE-2024-46677 — CVE-2024-46677 · CWE-476
gtp: fix NULL pointer dereference. When sockfd_lookup() fails, gtp_encap_enable_socket() returns a NULL pointer, but its callers only check for error pointers thus miss the NULL pointer case.
- CVE-2024-46679 — CVE-2024-46679 · CWE-362
In the Linux kernel, the following vulnerability has been resolved: ethtool: check device is present when getting link settings.
- CVE-2024-46685 — CVE-2024-46685 · CWE-476
pinctrl: single: fix NULL dereference in pcs_get_function(). pinmux_generic_get_function() can return NULL and the pointer 'function' was dereferenced without checking against NULL.
- CVE-2024-46689 — CVE-2024-46689 · CWE-20
soc: qcom: cmd-db: Map shared memory as WC, not WB Linux does not write into cmd-db region. This region of memory is write protected by XPU. XPU may sometime falsely detect clean cache eviction as "write" into the write protected region leading to secure interrupt which causes an endless loop somewhere in Trust Zone.
- CVE-2024-46702 — CVE-2024-46702 · CWE-20
thunderbolt: Mark XDomain as unplugged when router is removed.
- CVE-2024-46707 — CVE-2024-46707 · CWE-20
KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3 On a system with a GICv3, if a guest hasn't been configured with GICv3 and that the host is not capable of GICv2 emulation, a write to any of the ICC_*SGI*_EL1 registers is trapped to EL2.
- CVE-2024-46713 — CVE-2024-46713 · CWE-20
perf/aux: AUX buffer serialization.
- CVE-2024-46714 — CVE-2024-46714 · CWE-20
drm/amd/display: Skip wbscl_set_scaler_filter if filter is null Callers can pass null in filter (i.e. from returned from the function wbscl_get_filter_coeffs_16p) and a null check is added to ensure that is not the case.
- CVE-2024-46719 — CVE-2024-46719 · CWE-20
usb: typec: ucsi: Fix null pointer dereference in trace ucsi_register_altmode checks IS_ERR for the alt pointer and treats NULL as valid. When CONFIG_TYPEC_DP_ALTMODE is not enabled, ucsi_register_displayport returns NULL which causes a NULL pointer dereference in trace. Rather than return NULL, call typec_port_register_altmode to register DisplayPort alternate mode as a non-controllable mode when CONFIG_TYPEC_DP_ALTMODE is not enabled.
- CVE-2024-46721 — CVE-2024-46721 · CWE-20
apparmor: fix possible NULL pointer dereference. profile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made from __create_missing_ancestors(..) and 'ent->old' is NULL in aa_replace_profiles(..). In that case, it must return an error code and the code, -ENOENT represents its state that the path of its parent is not existed yet.
- CVE-2024-46722 — CVE-2024-46722 · CWE-20
drm/amdgpu: vulnerability due to an out-of-bounds read warning when accessing mc_data[i-1].
- CVE-2024-46723 — CVE-2024-46723 · CWE-20
drm/amdgpu: vulnerability due to an out-of-bounds read warning when accessing ucode[].
- CVE-2024-46724 — CVE-2024-46724 · CWE-20
drm/amdgpu: vulnerability in drm/amdgpu that involved an out-of-bounds read of df_v1_7_channel_number.
- CVE-2024-46725 — CVE-2024-46725 · CWE-20
drm/amdgpu: vulnerability caused by an out-of-bounds write warning due to an unchecked ring type value.
- CVE-2024-46731 — CVE-2024-46731 · CWE-20
drm/amd/pm: vulnerability caused by an out-of-bounds read warning where the index i - 1U can exceed the bounds of the mc_data[] array when i is zero.
- CVE-2024-46737 — CVE-2024-46737 · CWE-20
nvmet-tcp: kernel crash if commands allocation fails.
- CVE-2024-46738 — CVE-2024-46738 · CWE-20
VMCI: use-after-free when removing resource in vmci_resource_remove().
- CVE-2024-46739 — CVE-2024-46739 · CWE-20
uio_hv_generic: kernel NULL pointer dereference in hv_uio_rescind.
- CVE-2024-46740 — CVE-2024-46740 · CWE-20
binder: UAF caused by offsets overwrite.
- CVE-2024-46743 — CVE-2024-46743 · CWE-125
In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read in interrupt map walk.
- CVE-2024-46744 — CVE-2024-46744 · CWE-908
In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size.
- CVE-2024-46745 — CVE-2024-46745 · CWE-400
In the Linux kernel, the following vulnerability has been resolved: Input: uinput - reject requests with unreasonable number of slots When exercising uinput interface syzkaller may try setting up device with a really large number of slots, which causes memory allocation failure in input_mt_init_slots(). While this allocation failure is handled properly and request is rejected, it results in syzkaller reports. Additionally, such request may put undue burden on the system which will try to free a lot of memory for a bogus request. Fix it by limiting allowed number of slots to 100. This can easily be extended if we see devices that can track more than 100 contacts.
- CVE-2024-46747 — CVE-2024-46747 · CWE-20
HID: cougar: slab-out-of-bounds Read in cougar_report_fixup. Report_fixup for the Cougar 500k Gaming Keyboard was not verifying that the report descriptor size was correct before accessing it.
- CVE-2024-46750 — CVE-2024-46750 · CWE-413
In the Linux kernel, the following vulnerability has been resolved: PCI: Add missing bridge lock to pci_bus_lock().
- CVE-2024-46755 — CVE-2024-46755 · CWE-20
wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id(). mwifiex_get_priv_by_id() returns the priv pointer corresponding to the bss_num and bss_type, but without checking if the priv is actually currently in use. Unused priv pointers do not have a wiphy attached to them which can lead to NULL pointer dereferences further down the callstack.
- CVE-2024-46759 — CVE-2024-46759 · CWE-124
In the Linux kernel, the following vulnerability has been resolved: hwmon: (adc128d818) Fix underflows seen when writing limit attributes DIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large negative number such as -9223372036854775808 is provided by the user. Fix it by reordering clamp_val() and DIV_ROUND_CLOSEST() operations.
- CVE-2024-46761 — CVE-2024-46761 · CWE-20
pci/hotplug/pnv_php: hotplug driver crash on Powernv.
- CVE-2024-46763 — CVE-2024-46763 · CWE-20
fou: null-ptr-deref in GRO.
- CVE-2024-46771 — CVE-2024-46771 · CWE-20
can: bcm: Remove proc entry when dev is unregistered.
- CVE-2024-46777 — CVE-2024-46777 · CWE-20
udf: Avoid excessive partition lengths Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap.
- CVE-2024-46780 — CVE-2024-46780 · CWE-20
nilfs2: vulnerability caused by the need for mutual exclusion using nilfs->ns_sem when accessing superblock buffers in sysfs attribute show methods to prevent issues with pointer dereferencing and memory access.
- CVE-2024-46781 — CVE-2024-46781 · CWE-20
nilfs2: vulnerability involves a use-after-free bug during mount-time recovery, where inodes with recovered data are not freed if an error occurs before the log writer starts, leading to potential memory issues.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reported these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.