PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-38698 Siemens CVE debrief

CVE-2025-38698 was published by CISA on 2026-05-12 and republished on 2026-05-14 as ICSA-26-134-10. The supplied advisory text describes a corrupted regular file with a negative i_size value and says a check should be added when opening the file to avoid later failures. The source corpus also maps the advisory to Siemens SIMATIC CN 4100 versions before 5.0, but the description references the Linux kernel JFS, so applicability should be verified before taking action.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Operators and maintainers of Siemens SIMATIC CN 4100 deployments, especially versions earlier than 5.0, should review this advisory. Security and platform teams should also validate whether any Linux kernel/JFS-related component is actually in scope, because the supplied product mapping and vulnerability description do not fully align.

Technical summary

The advisory describes a file-corruption handling issue: a reproducer creates a corrupted file on disk with a negative i_size value, and the fix is to check for that condition when opening the file to prevent subsequent operation failures. The supplied CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a local, low-privilege, high-complexity issue with high impact if the affected condition is present.

Defensive priority

High, but verify applicability first due to the source/product mismatch.

Recommended defensive actions

  • Confirm whether any Siemens SIMATIC CN 4100 assets are running a version earlier than 5.0.
  • Review Siemens advisory SSA-032379 and the CISA ICS advisory ICSA-26-134-10 for vendor guidance.
  • Apply the vendor fix by updating to V5.0 or later where the advisory applies.
  • If you operate Linux kernel/JFS-based systems, cross-check patch status against the public CVE record because the supplied description references JFS corruption handling.
  • Schedule remediation in a maintenance window and validate normal file-handling behavior after the update.

Evidence notes

Evidence is limited to the supplied CISA CSAF advisory record and the Siemens references it lists. The corpus states the publication date as 2026-05-12 and the CISA republication date as 2026-05-14. The advisory text references a negative i_size corruption check, while the product mapping names Siemens SIMATIC CN 4100 vers:intdot/<5.0; this inconsistency is why the vendor confidence is low and human review is warranted.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-38698 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-38698

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-38698 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38698

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.