PatchSiren cyber security CVE debrief
CVE-2025-38236 Siemens CVE debrief
CVE-2025-38236 is a high-severity use-after-free in Linux kernel AF_UNIX stream receive handling. In the Siemens advisory, it is mapped to SIMATIC S7-1500 CPU MFP products that include an additional GNU/Linux subsystem. The source notes no fix was available at publication time and recommends restricting shell access and software provenance on affected devices.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
OT and industrial-control teams running the listed Siemens SIMATIC S7-1500 CPU MFP products, especially where the additional GNU/Linux subsystem is enabled and reachable by trusted or untrusted users. Linux kernel maintainers and defenders of embedded Linux environments should also track this issue because the root cause is in unix_stream_read_generic() and related AF_UNIX OOB handling.
Technical summary
The advisory describes a use-after-free in unix_stream_read_generic() caused by consecutive consumed out-of-band (OOB) sk_buffs remaining on the receive queue. A sequence of MSG_OOB reads can leave multiple consumed OOB skbs in place; a later non-OOB recv can then interact badly with SO_PEEK_OFF / manage_oob() logic, causing the code to free an skb that is later accessed again. The source cites a KASAN slab-use-after-free in unix_stream_read_actor and assigns CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Defensive priority
High. The issue is locally exploitable with low privileges on the affected Linux kernel path and is rated High by CVSS. For Siemens' mapped products, the source states no fix was available at the time of publication, so compensating controls matter immediately.
Recommended defensive actions
- Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources.
- Review whether the affected SIMATIC S7-1500 CPU MFP products are deployed in environments where local shell access or untrusted application execution is possible.
- Monitor Siemens and CISA advisory updates for a vendor fix or additional mitigation guidance.
- Use the referenced CISA industrial-control defensive practices and defense-in-depth guidance for layered access control and software provenance controls.
Evidence notes
CVE-2025-38236 was published on 2025-06-10 and the supplied source was last modified on 2026-05-14. The source advisory text identifies a Linux kernel AF_UNIX use-after-free in unix_stream_read_generic(), shows KASAN evidence, and maps the issue to Siemens SIMATIC S7-1500 CPU 1518-4/1518F-4 PN/DP MFP and SIPLUS variants. The remediation section explicitly says no fix is currently available and recommends restricting shell access and only running trusted applications.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38236 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38236
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38236 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38236
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.