PatchSiren cyber security CVE debrief
CVE-2025-38714 Siemens CVE debrief
CVE-2025-38714 is a Linux kernel memory-safety issue in hfsplus_bnode_read() that can produce a slab-out-of-bounds read. The supplied advisory data shows the fault being hit under KASAN during HFS+ metadata operations and assigns CVSS 3.1 vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. Because the source corpus is a republished Siemens/CISA advisory with product metadata that does not clearly match the Linux kernel description, scope should be validated before assuming product impact.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Linux administrators and security teams that run kernels with HFS+ filesystem support, especially on systems that may process untrusted or removable HFS+ media. OT and Siemens-focused teams should also verify whether the republished advisory actually applies to their SIMATIC CN 4100 deployments, since the supplied metadata appears inconsistent.
Technical summary
The advisory text says the Linux kernel issue is resolved by fixing a slab-out-of-bounds read in hfsplus_bnode_read(). The provided crash trace shows KASAN reporting an 8-byte read past a slab object while handling HFS+ bnode operations, with the stack reaching hfsplus_brec_remove(), __hfsplus_delete_attr(), hfsplus_delete_all_attrs(), and hfsplus_delete_cat() during an unlink path. The supplied CVSS vector indicates a local, low-privilege, no-UI attack path with high confidentiality, integrity, and availability impact if the vulnerable code path is reachable.
Defensive priority
High, with applicability validation first because the supplied advisory metadata is inconsistent.
Recommended defensive actions
- Apply the vendor-provided fix path listed in the advisory and update to V5.0 or later where applicable.
- Review whether any deployed systems actually use the affected Linux hfsplus code path or the Siemens product named in the republished advisory.
- Restrict exposure to removable or untrusted HFS+ media where practical.
- Monitor for filesystem-related crashes, KASAN-style findings, or unexpected behavior in HFS+ metadata operations on test and production systems.
- Use the official CISA and Siemens advisory links to confirm scope and remediation before scheduling changes.
Evidence notes
Source item ICSA-26-134-10 (published 2026-05-12, republished 2026-05-14) describes CVE-2025-38714 as a Linux kernel hfsplus_bnode_read() slab-out-of-bounds issue and includes a KASAN crash trace from an unlink-related path. The supplied remediation says to update to V5.0 or later, but the vendor/product metadata in the corpus is low confidence and appears inconsistent with the Linux kernel description, so applicability should be confirmed directly from the official advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38714 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38714
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38714 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38714
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.