PatchSiren cyber security CVE debrief
CVE-2025-38700 Siemens CVE debrief
CVE-2025-38700 is a Linux kernel libiscsi/iSER vulnerability republished in Siemens advisory ICSA-26-134-10 for SIMATIC CN 4100 vers:intdot/<5.0. The issue occurs when ib_fast_reg_mr allocation fails during iSER setup and iscsi_conn->dd_data is initialized even though no memory was allocated. During teardown, that bad state can lead to an invalid pointer dereference and a kernel panic. CISA’s advisory metadata rates the issue as high severity (CVSS 7.0) with local access and low privileges required.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Operators and administrators responsible for Siemens SIMATIC CN 4100 systems, especially environments using Linux kernel iSCSI/iSER paths or other storage workloads that rely on libiscsi. ICS teams should also care because the failure mode is a device or host crash/panic rather than a benign error.
Technical summary
The source advisory describes a logic flaw in scsi: libiscsi where iscsi_conn->dd_data is set unconditionally even when dd_size is zero. If ib_fast_reg_mr allocation fails during iSER setup, no buffer is allocated, but teardown later follows the invalid pointer and faults in swake_up_locked/complete during iscsi_iser_conn_stop. The result is a panic path triggered by connection stop handling. The advisory’s CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
High. The primary operational risk is kernel panic and service interruption on affected systems. Remediation is available and should be prioritized where the advisory applies.
Recommended defensive actions
- Update to Siemens V5.0 or later, as listed in the advisory remediation.
- Verify whether any affected SIMATIC CN 4100 deployments use the impacted Linux kernel storage path or iSER-related functionality.
- Review system hardening and access controls for storage-management paths; CISA ICS recommended practices are referenced in the advisory.
- Monitor affected hosts for unexpected kernel panics or repeated connection teardown failures until remediation is complete.
- Treat the Siemens product mapping as advisory-provided metadata and confirm exposure in your own asset inventory before scheduling maintenance.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-26-134-10 and its republished Siemens ProductCERT SSA-032379 content, both dated 2026-05-12 with a CISA republication on 2026-05-14. The advisory text states that an ib_fast_reg_mr allocation failure during iSER setup can leave iscsi_conn->dd_data initialized without allocated memory, leading to an invalid pointer dereference during connection teardown and a kernel panic. The source also lists the remediation as updating to V5.0 or later. The product mapping in the supplied source is marked low confidence and should be reviewed in local inventory.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38700 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38700
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38700 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38700
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.