PatchSiren cyber security CVE debrief
CVE-2025-38698 Siemens CVE debrief
CVE-2025-38698 was published by CISA on 2026-05-12 and republished on 2026-05-14 as ICSA-26-134-10. The supplied advisory text describes a corrupted regular file with a negative i_size value and says a check should be added when opening the file to avoid later failures. The source corpus also maps the advisory to Siemens SIMATIC CN 4100 versions before 5.0, but the description references the Linux kernel JFS, so applicability should be verified before taking action.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of Siemens SIMATIC CN 4100 deployments, especially versions earlier than 5.0, should review this advisory. Security and platform teams should also validate whether any Linux kernel/JFS-related component is actually in scope, because the supplied product mapping and vulnerability description do not fully align.
Technical summary
The advisory describes a file-corruption handling issue: a reproducer creates a corrupted file on disk with a negative i_size value, and the fix is to check for that condition when opening the file to prevent subsequent operation failures. The supplied CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a local, low-privilege, high-complexity issue with high impact if the affected condition is present.
Defensive priority
High, but verify applicability first due to the source/product mismatch.
Recommended defensive actions
- Confirm whether any Siemens SIMATIC CN 4100 assets are running a version earlier than 5.0.
- Review Siemens advisory SSA-032379 and the CISA ICS advisory ICSA-26-134-10 for vendor guidance.
- Apply the vendor fix by updating to V5.0 or later where the advisory applies.
- If you operate Linux kernel/JFS-based systems, cross-check patch status against the public CVE record because the supplied description references JFS corruption handling.
- Schedule remediation in a maintenance window and validate normal file-handling behavior after the update.
Evidence notes
Evidence is limited to the supplied CISA CSAF advisory record and the Siemens references it lists. The corpus states the publication date as 2026-05-12 and the CISA republication date as 2026-05-14. The advisory text references a negative i_size corruption check, while the product mapping names Siemens SIMATIC CN 4100 vers:intdot/<5.0; this inconsistency is why the vendor confidence is low and human review is warranted.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38698 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38698
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38698 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38698
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.