PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-38345 Siemens CVE debrief

CVE-2025-38345 was publicly disclosed in the Siemens/CISA advisory stream on 2026-01-28 and republished by CISA on 2026-02-25 after scope updates. The issue is a Linux kernel ACPICA operand cache leak that can surface during ACPI early termination on affected Siemens OT products, with Siemens directing customers to update to V3.3 or later.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-28
Original CVE updated
2026-02-25
Advisory published
2026-01-28
Advisory updated
2026-02-25

Who should care

Siemens OT/ICS operators running the affected RUGGEDCOM RST2428P or SCALANCE-family firmware, especially teams responsible for reboot reliability, firmware maintenance, and boot-chain integrity.

Technical summary

The corpus describes a bug in ACPICA’s dswstate.c where acpi_ds_obj_stack_pop_and_delete() miscalculates the top of the operand stack relative to acpi_ds_obj_stack_push(), leaving Acpi-Operand cache objects allocated when ACPI initialization terminates early. In the reported failure mode, a malformed or malicious ACPI table can force early termination, kmem_cache_destroy() reports that the slab cache still has objects, and the system continues booting after logging ACPI errors. The advisory assigns CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5). The source also notes that older kernels (<= 4.9) may expose stack-dump addresses, which is a hardening concern mentioned in the advisory rather than the scored impact.

Defensive priority

Medium. Plan remediation in the next maintenance window, but accelerate if the device is reboot-sensitive or if firmware/boot integrity cannot be tightly controlled.

Recommended defensive actions

  • Update affected Siemens products to V3.3 or later as directed in SSA-089022 / CISA ICSA-26-043-06.
  • Verify your exact device and firmware are in the affected-product list, since CISA’s republication updated the scope on 2026-02-24 and 2026-02-25.
  • Check boot logs for ACPI interpreter failures and 'Acpi-Operand' slab-cache messages to identify systems that may have hit the condition.
  • Apply ICS defense-in-depth practices and protect firmware/boot inputs from tampering, especially in environments where ACPI tables or boot media can be altered.
  • After updating, test a controlled reboot to confirm ACPI initialization completes normally and no cache-leak errors are logged.

Evidence notes

The supplied corpus explicitly states the ACPI operand cache leak, the stack-index mismatch in acpi_ds_obj_stack_pop_and_delete(), the boot-log signature ('kmem_cache_destroy Acpi-Operand: Slab cache still has objects'), and Siemens’ remediation to update to V3.3 or later. CISA’s revision history shows the advisory was initially published on 2026-01-28, republished on 2026-02-12, expanded on 2026-02-24, and updated again on 2026-02-25. The corpus does not provide a detailed firmware version range beyond the remediation statement.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-38345 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-38345

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-38345 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38345

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.