PatchSiren cyber security CVE debrief
CVE-2025-38058 Siemens CVE debrief
CVE-2025-38058 was published on 2025-06-10 and last updated on 2026-05-14. The advisory describes a race in Linux kernel __legitimize_mnt() where a check for MNT_SYNC_UMOUNT occurs outside mount_lock. In a narrow timing window around umount(2), that can let a mount reference count be raised after the victim has already been verified as not busy, which prevents the quiet undo path and can force a full mntput() later in caller context. Siemens and CISA map the issue to five SIMATIC/SIPLUS S7-1500 CPU products and state that no fix is currently available.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of the Siemens SIMATIC S7-1500 CPU family listed in the advisory, especially environments that use the additional GNU/Linux subsystem or expose its interactive shell. Security teams responsible for local access control, application trust, and patch tracking for those devices should prioritize this advisory.
Technical summary
The source description identifies a timing-sensitive reference-counting bug in the Linux kernel mount lifecycle. __legitimize_mnt() checks MNT_SYNC_UMOUNT before taking mount_lock, which can miss the state transition during umount(2). If the reference count is incremented after the mount has been judged not busy but before MNT_SYNC_UMOUNT is set, the function cannot safely revert the increment and leaves the later reference drop to the caller as a full mntput(). The published CVSS vector is local, low-privilege, no-user-interaction, with high availability impact only (CVSS 5.5, MEDIUM).
Defensive priority
Medium. The impact is limited to local availability, but the advisory lists affected Siemens OT products and says no fix is available yet, so compensating controls matter now.
Recommended defensive actions
- Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on the affected devices.
- Inventory the five advisory-listed Siemens SIMATIC/SIPLUS CPU variants and confirm exposure of the GNU/Linux subsystem.
- Monitor the Siemens ProductCERT advisory and CISA republication for any future remediation updates.
- Apply least-privilege access controls and administrative separation for operators who can reach the local shell or subsystem.
Evidence notes
The CVE description supplied in the source corpus states the race condition, the mount_lock ordering issue, and the potential for a full mntput() in caller context. The CISA CSAF source item maps CVE-2025-38058 to Siemens advisory ICSA-25-162-05 and lists five affected product IDs/names. The remediation entries explicitly say to restrict shell access to trusted personnel, use trusted software only, and that currently no fix is available.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38058 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38058
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38058 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38058
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.