ID

VAR-202406-1434


CVE

CVE-2024-38381


TITLE

Linux  of  Linux Kernel  Vulnerability in using uninitialized resources in

Trust: 0.8

sources: JVNDB: JVNDB-2024-007689

DESCRIPTION

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header size, payload size and total packet size before processing the packet. If an invalid packet is detected, it should be silently discarded. Linux of Linux Kernel Exists in the use of uninitialized resources.Information is obtained and service operation is interrupted (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs). Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server

Trust: 2.16

sources: NVD: CVE-2024-38381 // JVNDB: JVNDB-2024-007689 // CNVD: CNVD-2025-19346

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-19346

AFFECTED PRODUCTS

vendor:linuxmodel:kernelscope:gteversion:6.1.85

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.10.219

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.15.161

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.10.215

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.1.93

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.9.4

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.8.5

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.19.312

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.4.278

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.6.26

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.19.316

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.6.33

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.4.274

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.15.154

Trust: 1.0

vendor:linuxmodel:kernelscope:eqversion:5.10.215 that's all 5.10.219

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:4.19.312 that's all 6.19.316

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.8.5 that's all 6.9.4

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.1.85 that's all 6.1.93

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:5.4.274 that's all 5.4.278

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:5.15.154 that's all 5.15.161

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion: -

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.6.26 that's all 6.6.33

Trust: 0.8

vendor:siemensmodel:ruggedcom rst2428pscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xc-300/xr-300/xc-400/xr-500wg/xr-500 familyscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xcm-/xrm-/xch-/xrh-300 familyscope:ltversion:v3.1

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007689 // NVD: CVE-2024-38381

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-38381
value: HIGH

Trust: 1.0

NVD: CVE-2024-38381
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-19346
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-19346
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-38381
baseSeverity: HIGH
baseScore: 7.1
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2024-38381
baseSeverity: HIGH
baseScore: 7.1
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007689 // NVD: CVE-2024-38381

PROBLEMTYPE DATA

problemtype:CWE-908

Trust: 1.0

problemtype:Use of uninitialized resources (CWE-908) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-007689 // NVD: CVE-2024-38381

PATCH

title:Linux Kernel Archivesurl:https://git.kernel.org/stable/c/017ff397624930fd7ac7f1761f3c9d6a7100f68c

Trust: 0.8

title:Patch for Multiple vulnerabilities in Siemens SINEC OS third-party componentsurl:https://www.cnvd.org.cn/patchInfo/show/723071

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007689

EXTERNAL IDS

db:NVDid:CVE-2024-38381

Trust: 2.6

db:SIEMENSid:SSA-613116

Trust: 1.6

db:SIEMENSid:SSA-265688

Trust: 1.0

db:JVNDBid:JVNDB-2024-007689

Trust: 0.8

db:CNVDid:CNVD-2025-19346

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007689 // NVD: CVE-2024-38381

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-613116.html

Trust: 1.6

url:https://git.kernel.org/stable/c/e53a7f8afcbd2886f2a94c5d56757328109730ea

Trust: 1.0

url:https://git.kernel.org/stable/c/e8c8e0d0d214c877fbad555df5b3ed558cd9b0c3

Trust: 1.0

url:https://git.kernel.org/stable/c/406cfac9debd4a6d3dc5d9258ee086372a8c08b6

Trust: 1.0

url:https://git.kernel.org/stable/c/e4a87abf588536d1cdfb128595e6e680af5cf3ed

Trust: 1.0

url:https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

Trust: 1.0

url:https://git.kernel.org/stable/c/017ff397624930fd7ac7f1761f3c9d6a7100f68c

Trust: 1.0

url:https://git.kernel.org/stable/c/ad4d196d2008c7f413167f0a693feb4f0439d7fe

Trust: 1.0

url:https://git.kernel.org/stable/c/485ded868ed62ceb2acb3a459d7843fd71472619

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-265688.html

Trust: 1.0

url:https://git.kernel.org/stable/c/f80b786ab0550d0020191a59077b2c7e069db2d1

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-38381

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-007689 // NVD: CVE-2024-38381

SOURCES

db:CNVDid:CNVD-2025-19346
db:JVNDBid:JVNDB-2024-007689
db:NVDid:CVE-2024-38381

LAST UPDATE DATE

2026-06-18T20:37:59.970000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-22T00:00:00
db:JVNDBid:JVNDB-2024-007689date:2024-09-10T04:22:00
db:NVDid:CVE-2024-38381date:2026-05-12T12:16:52.053

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-12T00:00:00
db:JVNDBid:JVNDB-2024-007689date:2024-09-10T00:00:00
db:NVDid:CVE-2024-38381date:2024-06-21T11:15:10.757