PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21864 Siemens CVE debrief

CVE-2025-21864 is a Linux kernel availability issue affecting Siemens SIMATIC S7-1500 CPU 1518 MFP-family products in the supplied advisory. The reported bug can leave a secpath-linked reference to xfrm_state attached to an skb during deferred cleanup, so the reference is still present when a network namespace is deleted. In the source description, this can trigger a WARN in xfrm6_tunnel_net_exit during TCP/ipcomp6 testing and create an availability problem. Siemens/CISA list the issue as medium severity, and the supplied advisory states that no fix is currently available.

Vendor
Siemens
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

OT defenders, platform owners, and maintenance teams responsible for the listed Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP and 1518F-4 PN/DP MFP variants, especially environments that use the GNU/Linux subsystem or rely on Linux network-stack functionality exposed by the device.

Technical summary

The advisory describes a Linux TCP receive-path cleanup problem: the skb’s destination entry is dropped when it is no longer needed, but the secpath was not dropped at the same time. Because secpath retains a reference to xfrm_state, deferred freeing of the skb can keep that reference alive until after network namespace teardown. If the defer list is not flushed before the netns is deleted, xfrm_state objects remain referenced unexpectedly and xfrm6_tunnel_net_exit can warn. The source notes that tcp_filter has already called LSM hooks that may need secpath, but also that MPTCP-related extensions may still be present, so not every skb extension can be removed wholesale. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5, Medium).

Defensive priority

Medium. The issue is local and availability-focused, but it affects an OT product family and the source advisory says no fix is available yet, so affected operators should track vendor guidance closely and apply available hardening measures.

Recommended defensive actions

  • Identify whether any of the listed Siemens SIMATIC S7-1500 CPU models are deployed in your environment and confirm whether they use the affected GNU/Linux subsystem or related network features.
  • Review and follow Siemens ProductCERT advisory SSA-082556 and the CISA advisory for updates, since the supplied source states that no fix is currently available.
  • Restrict interactive shell access to trusted personnel only, as recommended in the source remediation guidance.
  • Only build and run applications from trusted sources on affected devices, per the source remediation guidance.
  • Monitor for future vendor updates or revised mitigation guidance and plan maintenance windows so they can be applied promptly when available.

Evidence notes

The affected products, no-fix status, remediations, CVSS vector, and publication/modification dates come from the supplied CISA CSAF source and its referenced Siemens advisory materials. The technical mechanism is taken from the provided CVE description: a secpath/xfrm_state reference can survive deferred skb freeing and remain present during netns teardown. PublishedAt is 2025-06-10T00:00:00.000Z and ModifiedAt is 2026-05-14T06:00:00.000Z; those are the dates used for timing context. The provided data also marks the issue as not in KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21864 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21864

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21864 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21864

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.