PatchSiren cyber security CVE debrief
CVE-2025-21767 Siemens CVE debrief
CVE-2025-21767 is a Linux kernel bug called out in Siemens/CISA advisory ICSA-25-162-05 for specific Siemens SIMATIC S7-1500 CPU 1518-* MFP and SIPLUS variants. The issue is tied to PREEMPT_RT behavior in the clocksource watchdog path: clocksource_verify_choose_cpus() can call get_random_u32() while preemption is disabled, which may hit sleeping locks and trigger a kernel BUG. The published advisory rates the issue CVSS 3.1 5.5 (Medium) and states that no fix is currently available in the vendor advisory.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Siemens SIMATIC S7-1500 operators, OT/ICS security teams, and integrators responsible for the affected CPU models, especially where the additional GNU/Linux subsystem is used or where Linux kernel behavior is relevant.
Technical summary
The root cause is an atomic-context violation in the Linux clocksource watchdog CPU selection path. clocksource_verify_choose_cpus() runs with preemption disabled and invokes get_random_u32() to select CPUs. On PREEMPT_RT kernels, the entropy-related locks involved in that call are sleeping locks, so taking them from atomic context can produce a 'sleeping function called from invalid context' warning and a kernel BUG. The upstream fix described in the source uses migrate_disable() so smp_processor_id() can be used reliably without introducing atomic context, then applies preempt_disable() later to avoid unexpected latency during the measurement path.
Defensive priority
Medium — prioritize affected OT deployments because the issue can destabilize the Linux subsystem and the advisory says no vendor fix is currently available.
Recommended defensive actions
- Inventory the listed Siemens SIMATIC S7-1500 and SIPLUS CPU models and confirm whether the additional GNU/Linux subsystem is enabled in your deployment.
- Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on affected devices.
- Monitor Siemens ProductCERT and CISA advisory updates for remediation guidance or a vendor fix.
- If you maintain custom Linux builds, verify whether the upstream migrate_disable() fix is present where applicable.
- Follow CISA ICS defense-in-depth and recommended-practices guidance for layered protection while awaiting remediation.
Evidence notes
The supplied advisory describes a PREEMPT_RT kernel bug that can call get_random_u32() in atomic context, causing a sleeping-function warning and kernel BUG. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which supports an availability-focused impact. The source advisory lists five affected Siemens CPU variants and explicitly states 'Currently no fix is available.' Timing context: the CVE/public advisory date is 2025-06-10, and the latest supplied source modification is 2026-05-14; those are publication/update dates, not the issue creation date.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21767 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21767
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21767 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21767
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.