PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-38477 Siemens CVE debrief

CVE-2025-38477 was publicly disclosed in CISA’s ICSA-25-162-05 advisory on 2025-06-10 and last updated on 2026-05-14. The advisory ties a Linux kernel sch_qfq race condition to affected Siemens SIMATIC S7-1500 CPU family products, with potential for local denial of service through NULL dereference or use-after-free conditions. Siemens/CISA note that no fix is currently available and recommend access restriction and trusted-source controls as mitigations.

Vendor
Siemens
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
MEDIUM 4.7
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

OT and industrial-control operators running the affected Siemens SIMATIC S7-1500 CPU family products, especially where the additional GNU/Linux subsystem is exposed or used. Security and platform teams should care if local users, shell access, or locally running applications are permitted on these devices, because the issue is reachable with local access and can affect availability.

Technical summary

The source advisory describes a race condition in Linux kernel sch_qfq qfq_aggregate handling: qfq_change_agg, called during qfq_enqueue, can modify agg while other threads access it concurrently. The documented symptoms include a NULL dereference in qfq_dump_class and a use-after-free in qfq_delete_class. The referenced patch moves qfq_destroy_class into the critical section and adds sch_tree_lock protection to qfq_dump_class and qfq_dump_class_stats.

Defensive priority

Medium. The issue is locally reachable, requires low-privilege local access, and is documented as an availability-impacting race condition. For affected Siemens products, the advisory also states that no fix is currently available, so compensating controls matter now.

Recommended defensive actions

  • Restrict access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
  • Allow only trusted, vetted applications to be built and run on affected devices.
  • Inventory the affected Siemens SIMATIC S7-1500 CPU family products and identify where local shell or application access is enabled.
  • Monitor affected systems for unexpected crashes, kernel faults, or instability consistent with NULL dereference or use-after-free behavior.
  • Track Siemens and CISA advisory updates for a vendor fix or revised mitigation guidance.

Evidence notes

CISA CSAF ICSA-25-162-05 identifies the affected Siemens product family and states "Currently no fix is available". The advisory’s description says the Linux kernel sch_qfq race can occur when agg is modified in qfq_change_agg during qfq_enqueue while other threads access it concurrently, with qfq_dump_class potentially triggering a NULL dereference and qfq_delete_class potentially causing a use-after-free. The advisory also records CVSS 3.1 vector AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H, which supports a local, availability-focused risk profile. The supplied remediations are access restriction and trusted-source controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-38477 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-38477

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-38477 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38477

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.