PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21767 Siemens CVE debrief

CVE-2025-21767 is a Linux kernel bug called out in Siemens/CISA advisory ICSA-25-162-05 for specific Siemens SIMATIC S7-1500 CPU 1518-* MFP and SIPLUS variants. The issue is tied to PREEMPT_RT behavior in the clocksource watchdog path: clocksource_verify_choose_cpus() can call get_random_u32() while preemption is disabled, which may hit sleeping locks and trigger a kernel BUG. The published advisory rates the issue CVSS 3.1 5.5 (Medium) and states that no fix is currently available in the vendor advisory.

Vendor
Siemens
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

Siemens SIMATIC S7-1500 operators, OT/ICS security teams, and integrators responsible for the affected CPU models, especially where the additional GNU/Linux subsystem is used or where Linux kernel behavior is relevant.

Technical summary

The root cause is an atomic-context violation in the Linux clocksource watchdog CPU selection path. clocksource_verify_choose_cpus() runs with preemption disabled and invokes get_random_u32() to select CPUs. On PREEMPT_RT kernels, the entropy-related locks involved in that call are sleeping locks, so taking them from atomic context can produce a 'sleeping function called from invalid context' warning and a kernel BUG. The upstream fix described in the source uses migrate_disable() so smp_processor_id() can be used reliably without introducing atomic context, then applies preempt_disable() later to avoid unexpected latency during the measurement path.

Defensive priority

Medium — prioritize affected OT deployments because the issue can destabilize the Linux subsystem and the advisory says no vendor fix is currently available.

Recommended defensive actions

  • Inventory the listed Siemens SIMATIC S7-1500 and SIPLUS CPU models and confirm whether the additional GNU/Linux subsystem is enabled in your deployment.
  • Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
  • Only build and run applications from trusted sources on affected devices.
  • Monitor Siemens ProductCERT and CISA advisory updates for remediation guidance or a vendor fix.
  • If you maintain custom Linux builds, verify whether the upstream migrate_disable() fix is present where applicable.
  • Follow CISA ICS defense-in-depth and recommended-practices guidance for layered protection while awaiting remediation.

Evidence notes

The supplied advisory describes a PREEMPT_RT kernel bug that can call get_random_u32() in atomic context, causing a sleeping-function warning and kernel BUG. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which supports an availability-focused impact. The source advisory lists five affected Siemens CPU variants and explicitly states 'Currently no fix is available.' Timing context: the CVE/public advisory date is 2025-06-10, and the latest supplied source modification is 2026-05-14; those are publication/update dates, not the issue creation date.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21767 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21767

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21767 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21767

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.