PatchSiren cyber security CVE debrief
CVE-2025-38681 Siemens CVE debrief
CVE-2025-38681 is a race condition in Linux kernel ptdump page-table inspection paths. During memory hot-remove, kernel page tables can change while ptdump_walk_pgd() or ptdump_check_wx() is reading them. In the worst case, freed intermediate page-table memory can be reused, letting the dump code dereference stale pointers and potentially crash or otherwise misbehave. The provided advisory data ties the issue to a Siemens SIMATIC CN 4100 record, but that product association is low-confidence and should be verified against the linked vendor advisory.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Linux kernel maintainers, OT/ICS administrators, and platform teams responsible for systems that expose kernel page-table debug interfaces or include the affected ptdump paths. Treat the Siemens SIMATIC CN 4100 product mapping as needing verification.
Technical summary
The source advisory describes a race between kernel page-table dumping and concurrent memory hotplug teardown. Leaf-entry changes can produce stale output, but freeing intermediate page-table levels creates a use-after-free risk inside the ptdump traversal. The fix moves the memory hotplug lock into the generic ptdump path so both kernel_page_tables and check_wx_pages use consistent synchronization. The supplied CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H (6.5, Medium).
Defensive priority
Medium
Recommended defensive actions
- Apply the vendor-fixed release identified in the source advisory: update to V5.0 or later.
- Verify whether your environment actually uses the affected Siemens mapping or the underlying Linux kernel ptdump code, since the source record’s product association is low-confidence.
- Prioritize systems where local users can access kernel debugfs or page-table inspection interfaces.
- Review kernel update cadence for OT/ICS appliances and Linux-based embedded devices that inherit the affected kernel code.
- Confirm the fix by checking the linked Siemens ProductCERT and CISA advisory records for the final affected-version matrix.
Evidence notes
The supplied CISA CSAF source (ICSA-26-134-10) was published on 2026-05-12 and republished on 2026-05-14. Its description explains the race in mm/ptdump and the synchronization change that moves the memory hotplug lock into the generic ptdump path. The source record also maps the CVE to Siemens SIMATIC CN 4100 vers:intdot/<5.0, but that mapping is marked low-confidence in the prompt and should be verified against the linked vendor advisory. No KEV entry is provided in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38681 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38681
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38681 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38681
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.