ID

VAR-202406-2580


CVE

CVE-2024-38587


TITLE

Linux  of  Linux Kernel  Vulnerability in array index validation in

Trust: 0.8

sources: JVNDB: JVNDB-2024-021928

DESCRIPTION

In the Linux kernel, the following vulnerability has been resolved: speakup: Fix sizeof() vs ARRAY_SIZE() bug The "buf" pointer is an array of u16 values. This code should be using ARRAY_SIZE() (which is 256) instead of sizeof() (which is 512), otherwise it can the still got out of bounds. Linux of Linux Kernel Exists in an array index validation vulnerability.Service operation interruption (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs). Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server

Trust: 2.16

sources: NVD: CVE-2024-38587 // JVNDB: JVNDB-2024-021928 // CNVD: CNVD-2025-19346

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-19346

AFFECTED PRODUCTS

vendor:linuxmodel:kernelscope:ltversion:6.8.12

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.6.29

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.10.219

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.1.88

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.10.216

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.8.8

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.9

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.4.275

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.1.93

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.15.157

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.9.3

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.4.278

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.19.316

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.6.33

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.19.313

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.15.161

Trust: 1.0

vendor:linuxmodel:kernelscope:eqversion:4.19.313 that's all 4.19.316

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion: -

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:5.10.216 that's all 5.10.219

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:5.15.157 that's all 5.15.161

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.6.29 that's all 6.6.33

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.8.8 that's all 6.8.12

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:5.4.275 that's all 5.4.278

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.9 that's all 6.9.3

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.1.88 that's all 6.1.93

Trust: 0.8

vendor:siemensmodel:ruggedcom rst2428pscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xc-300/xr-300/xc-400/xr-500wg/xr-500 familyscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xcm-/xrm-/xch-/xrh-300 familyscope:ltversion:v3.1

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-021928 // NVD: CVE-2024-38587

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-38587
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2024-021928
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2025-19346
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-19346
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-38587
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

OTHER: JVNDB-2024-021928
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-021928 // NVD: CVE-2024-38587

PROBLEMTYPE DATA

problemtype:CWE-129

Trust: 1.0

problemtype:Improper validation of array indexes (CWE-129) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-021928 // NVD: CVE-2024-38587

PATCH

title:Linux Kernel Archivesurl:https://git.kernel.org/stable/c/008ab3c53bc4f0b2f20013c8f6c204a3203d0b8b

Trust: 0.8

title:Patch for Multiple vulnerabilities in Siemens SINEC OS third-party componentsurl:https://www.cnvd.org.cn/patchInfo/show/723071

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-021928

EXTERNAL IDS

db:NVDid:CVE-2024-38587

Trust: 2.6

db:SIEMENSid:SSA-613116

Trust: 1.6

db:SIEMENSid:SSA-265688

Trust: 1.0

db:JVNDBid:JVNDB-2024-021928

Trust: 0.8

db:CNVDid:CNVD-2025-19346

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-021928 // NVD: CVE-2024-38587

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-613116.html

Trust: 1.6

url:https://git.kernel.org/stable/c/504178fb7d9f6cdb0496d5491efb05f45597e535

Trust: 1.0

url:https://git.kernel.org/stable/c/3726f75a1ccc16cd335c0ccfad1d92ee08ecba5e

Trust: 1.0

url:https://git.kernel.org/stable/c/d52c04474feac8e305814a5228e622afe481b2ef

Trust: 1.0

url:https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

Trust: 1.0

url:https://git.kernel.org/stable/c/07ef95cc7a579731198c93beed281e3a79a0e586

Trust: 1.0

url:https://git.kernel.org/stable/c/c6e1650cf5df1bd6638eeee231a683ef30c7d4eb

Trust: 1.0

url:https://git.kernel.org/stable/c/008ab3c53bc4f0b2f20013c8f6c204a3203d0b8b

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-265688.html

Trust: 1.0

url:https://git.kernel.org/stable/c/eb1ea64328d4cc7d7a912c563f8523d5259716ef

Trust: 1.0

url:https://git.kernel.org/stable/c/cd7f3978c2ec741aedd1d860b2adb227314cf996

Trust: 1.0

url:https://git.kernel.org/stable/c/42f0a3f67158ed6b2908d2b9ffbf7e96d23fd358

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-38587

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-021928 // NVD: CVE-2024-38587

SOURCES

db:CNVDid:CNVD-2025-19346
db:JVNDBid:JVNDB-2024-021928
db:NVDid:CVE-2024-38587

LAST UPDATE DATE

2026-06-18T18:21:23.214000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-22T00:00:00
db:JVNDBid:JVNDB-2024-021928date:2025-04-11T08:58:00
db:NVDid:CVE-2024-38587date:2026-05-12T12:16:53.990

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-12T00:00:00
db:JVNDBid:JVNDB-2024-021928date:2025-04-11T00:00:00
db:NVDid:CVE-2024-38587date:2024-06-19T14:15:18.800