PatchSiren cyber security CVE debrief
CVE-2025-21764 Siemens CVE debrief
CVE-2025-21764 is a HIGH severity vulnerability (CVSS 7.8) affecting the Linux kernel's IPv6 Neighbor Discovery (NDISC) subsystem. The issue involves missing RCU (Read-Copy-Update) protection in the ndisc_alloc_skb() function, which can lead to use-after-free conditions. This vulnerability was published on April 9, 2024, and most recently modified on May 14, 2026. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP industrial control system. The vulnerability requires local access with low privileges to exploit, but successful exploitation can result in complete compromise of confidentiality, integrity, and availability. No patch is currently available from Siemens; mitigation relies on restricting access to trusted personnel and ensuring only trusted applications are executed.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Industrial control system operators, OT security teams, Siemens SIMATIC S7-1500 TM MFP administrators, critical infrastructure security personnel, and organizations running affected PLC systems in manufacturing, energy, water treatment, or other industrial sectors should prioritize this vulnerability due to the lack of available patches and high potential impact.
Technical summary
The vulnerability exists in the Linux kernel's ndisc_alloc_skb() function within the IPv6 Neighbor Discovery subsystem. The function lacks proper RCU protection, creating a race condition that can lead to use-after-free memory corruption. This is classified as CWE-416 (Use After Free). The attack requires local access with low privileges but enables complete system compromise. The affected product is the GNU/Linux subsystem embedded in Siemens SIMATIC S7-1500 TM MFP programmable logic controllers used in industrial automation environments.
Defensive priority
HIGH
Recommended defensive actions
- Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
- Implement application whitelisting to ensure only trusted applications execute on affected systems
- Monitor for anomalous local process activity on SIMATIC S7-1500 TM MFP systems
- Apply vendor patches immediately upon release from Siemens
- Segment affected industrial control systems from untrusted networks
- Review and implement CISA ICS recommended practices for defense in depth
Evidence notes
The vulnerability description 'ndisc: use RCU protection in ndisc_alloc_skb()' indicates a kernel-level memory safety issue in IPv6 neighbor discovery. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms local attack vector with high impact. Siemens' CSAF data explicitly lists this CVE against the SIMATIC S7-1500 TM MFP GNU/Linux subsystem with no fix available.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21764 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21764
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21764 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21764
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.