PatchSiren cyber security CVE debrief
CVE-2025-21864 Siemens CVE debrief
CVE-2025-21864 is a Linux kernel availability issue affecting Siemens SIMATIC S7-1500 CPU 1518 MFP-family products in the supplied advisory. The reported bug can leave a secpath-linked reference to xfrm_state attached to an skb during deferred cleanup, so the reference is still present when a network namespace is deleted. In the source description, this can trigger a WARN in xfrm6_tunnel_net_exit during TCP/ipcomp6 testing and create an availability problem. Siemens/CISA list the issue as medium severity, and the supplied advisory states that no fix is currently available.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
OT defenders, platform owners, and maintenance teams responsible for the listed Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP and 1518F-4 PN/DP MFP variants, especially environments that use the GNU/Linux subsystem or rely on Linux network-stack functionality exposed by the device.
Technical summary
The advisory describes a Linux TCP receive-path cleanup problem: the skb’s destination entry is dropped when it is no longer needed, but the secpath was not dropped at the same time. Because secpath retains a reference to xfrm_state, deferred freeing of the skb can keep that reference alive until after network namespace teardown. If the defer list is not flushed before the netns is deleted, xfrm_state objects remain referenced unexpectedly and xfrm6_tunnel_net_exit can warn. The source notes that tcp_filter has already called LSM hooks that may need secpath, but also that MPTCP-related extensions may still be present, so not every skb extension can be removed wholesale. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5, Medium).
Defensive priority
Medium. The issue is local and availability-focused, but it affects an OT product family and the source advisory says no fix is available yet, so affected operators should track vendor guidance closely and apply available hardening measures.
Recommended defensive actions
- Identify whether any of the listed Siemens SIMATIC S7-1500 CPU models are deployed in your environment and confirm whether they use the affected GNU/Linux subsystem or related network features.
- Review and follow Siemens ProductCERT advisory SSA-082556 and the CISA advisory for updates, since the supplied source states that no fix is currently available.
- Restrict interactive shell access to trusted personnel only, as recommended in the source remediation guidance.
- Only build and run applications from trusted sources on affected devices, per the source remediation guidance.
- Monitor for future vendor updates or revised mitigation guidance and plan maintenance windows so they can be applied promptly when available.
Evidence notes
The affected products, no-fix status, remediations, CVSS vector, and publication/modification dates come from the supplied CISA CSAF source and its referenced Siemens advisory materials. The technical mechanism is taken from the provided CVE description: a secpath/xfrm_state reference can survive deferred skb freeing and remain present during netns teardown. PublishedAt is 2025-06-10T00:00:00.000Z and ModifiedAt is 2026-05-14T06:00:00.000Z; those are the dates used for timing context. The provided data also marks the issue as not in KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21864 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21864
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21864 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21864
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.