PatchSiren cyber security CVE debrief
CVE-2025-38067 Siemens CVE debrief
CVE-2025-38067 describes a Linux kernel rseq registration flaw that can trigger a segfault when rseq_cs is non-zero. In the supplied Siemens/CISA advisory context, the issue is mapped to specific SIMATIC S7-1500 CPU variants and the advisory lists no fix at the time of publication, only compensating mitigations.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of the listed Siemens SIMATIC S7-1500 CPU variants, OT/ICS security teams, and anyone running the additional GNU/Linux subsystem or related software on affected deployments should pay attention.
Technical summary
The source description says the kernel does not currently enforce the documented requirement that user space zero rseq_cs before registration. If a non-zero value is present, return to user space can segfault because the pointer may not reference a valid struct rseq_cs. The advisory notes a kernel-side workaround that clears rseq_cs on registration to avoid crashes while preserving compatibility with older glibc behavior that reuses rseq areas without clearing the field. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with a local availability-impact issue.
Defensive priority
Medium, with higher attention for environments that actually run the affected Siemens product variants.
Recommended defensive actions
- Confirm whether any of the listed affected Siemens SIMATIC S7-1500 CPU variants are deployed in your environment.
- Review Siemens/CISA advisory ICSA-25-162-05 and track for vendor updates, since the supplied advisory lists no fix available.
- Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on the affected systems.
- Plan compensating controls and maintenance windows around the availability risk rather than assuming a security patch is already available.
Evidence notes
Primary evidence comes from the CISA CSAF source item for ICSA-25-162-05 and its linked Siemens ProductCERT advisory SSA-082556. The source metadata shows publication on 2025-06-10 and a later republication update on 2026-05-14; those later updates should not be treated as the CVE issue date. The advisory content ties CVE-2025-38067 to five Siemens SIMATIC S7-1500 CPU product variants and states 'Currently no fix is available.'
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38067 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38067
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38067 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38067
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.