PatchSiren cyber security CVE debrief
CVE-2025-38400 Siemens CVE debrief
CVE-2025-38400 is a reliability and availability issue tied in the supplied advisory corpus to Siemens SIMATIC S7-1500 CPU product entries, while the vulnerability text itself describes a Linux kernel NFS proc cleanup bug. The reported failure path leaves /proc/net/rpc/nfs in place when nfs_fs_proc_net_init() fails, and a later rpc_proc_exit() cleanup attempt logs a warning because /proc/net/rpc is not empty. The result is a kernel warning and cleanup inconsistency rather than a confidentiality or integrity break. The source record shows the issue was published on 2025-06-10 and later republished/updated on 2026-05-14.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers who rely on the affected Siemens product set in the supplied advisory, and Linux kernel integrators or platform teams that include NFS and procfs support in their builds. Security teams should pay attention because the issue is locally triggerable and can surface during namespace or network-stack teardown paths.
Technical summary
The vulnerability description states that a fault-injected failure in nfs_fs_proc_net_init() can prevent /proc/net/rpc/nfs from being removed. When the system later runs rpc_proc_exit(), the procfs hierarchy is not empty, so remove_proc_entry() emits a warning about leaking at least 'nfs'. The supplied evidence includes a syzbot report showing the failure triggered through slab allocation fault injection during proc_create_net_data() and then observed during network namespace teardown. The advisory’s CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local issue with availability impact.
Defensive priority
Medium. The issue is not described as remote code execution or data exposure, but it can cause kernel warnings and cleanup failures in a privileged local path. Because the source advisory ties it to an industrial product family, validation of exposure and firmware/software versioning should be prioritized.
Recommended defensive actions
- Verify whether any deployed Siemens product or Linux-based runtime in your environment matches the affected advisory scope listed in the source record.
- Apply vendor-provided updates or firmware/software revisions as soon as they are available for the affected product set.
- Review whether NFS and related procfs cleanup paths are present in your Linux kernel builds and ensure you are on a version that includes the fix described by the advisory.
- Monitor for repeated kernel warnings involving remove_proc_entry(), /proc/net/rpc, or NFS namespace teardown.
- Use the source-listed hardening guidance where applicable, including limiting interactive shell access to trusted personnel and running only trusted applications.
Evidence notes
The supplied description says: 'nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails.' It also includes a syzbot fault-injection trace showing failure in nfs_fs_proc_net_init() and a later warning: 'remove_proc_entry: removing non-empty directory 'net/rpc', leaking at least 'nfs''. The source CSAF metadata associates CVE-2025-38400 with Siemens SIMATIC S7-1500 CPU product entries and lists the issue publication date as 2025-06-10, with a latest update on 2026-05-14. The source remediations section states 'Currently no fix is available', so product-specific mitigation should be validated directly against the vendor advisory and current firmware/software status.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38400 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38400
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38400 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38400
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.