PatchSiren cyber security CVE debrief
CVE-2025-38670 Siemens CVE debrief
CVE-2025-38670 is a Linux kernel arm64 entry-path flaw that can leave the task stack and Shadow Call Stack out of sync if an interrupt lands during stack switching. The source advisory says this can clobber stack state and lead to kernel panics or other availability failures. In the supplied advisory metadata, Siemens maps the issue to SIMATIC CN 4100 versions prior to 5.0 and recommends updating to V5.0 or later.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
OT defenders, embedded Linux maintainers, and Siemens SIMATIC CN 4100 operators on affected versions; also Linux arm64 platform owners using Shadow Call Stack, pseudo-NMI-like configurations, or other interrupt-heavy deployments.
Technical summary
According to the source advisory, cpu_switch_to() and call_on_irq_stack() change SP and the Shadow Call Stack pointer in separate steps, so an SErrors or Debug Exception can interrupt the transition and leave SP and x18 pointing at different tasks or stacks. That mismatch can cause the wrong SCS pointer to be saved or reused, clobbering task state and potentially triggering kernel panics. The fix masks DAIF during cpu_switch_to() and around the stack-switch branch in call_on_irq_stack(), and uses an assembly macro to save and mask DAIF consistently.
Defensive priority
Medium. The published CVSS is 5.5/Medium, but the main consequence is availability loss in kernel space, which can be operationally significant for OT and embedded systems.
Recommended defensive actions
- Apply the vendor remediation and update Siemens SIMATIC CN 4100 to V5.0 or later, as stated in the advisory.
- Verify whether any deployed systems use affected arm64 kernel builds or configurations that enable Shadow Call Stack or pseudo-NMI behavior.
- Prioritize patching systems where a kernel panic would have operational or safety impact, especially in OT environments.
- Monitor for unexplained kernel panics, stack corruption symptoms, or repeated reboot events on affected devices.
- Confirm firmware/software provenance before and after remediation so the fix is sourced from the official Siemens update path.
Evidence notes
The supplied CISA CSAF advisory ICSA-26-134-10 was published on 2026-05-12 and republished on 2026-05-14 with Siemens ProductCERT SSA-032379 as the referenced vendor advisory. The advisory metadata assigns the issue to Siemens SIMATIC CN 4100 versions prior to 5.0 and provides the remediation to update to V5.0 or later. The vulnerability description in the source corpus attributes the underlying flaw to Linux kernel arm64 entry code involving cpu_switch_to() and call_on_irq_stack(). The product attribution is low confidence in the provided metadata, so it should be treated carefully.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38670 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38670
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38670 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38670
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.