PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-38714 Siemens CVE debrief

CVE-2025-38714 is a Linux kernel memory-safety issue in hfsplus_bnode_read() that can produce a slab-out-of-bounds read. The supplied advisory data shows the fault being hit under KASAN during HFS+ metadata operations and assigns CVSS 3.1 vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. Because the source corpus is a republished Siemens/CISA advisory with product metadata that does not clearly match the Linux kernel description, scope should be validated before assuming product impact.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Linux administrators and security teams that run kernels with HFS+ filesystem support, especially on systems that may process untrusted or removable HFS+ media. OT and Siemens-focused teams should also verify whether the republished advisory actually applies to their SIMATIC CN 4100 deployments, since the supplied metadata appears inconsistent.

Technical summary

The advisory text says the Linux kernel issue is resolved by fixing a slab-out-of-bounds read in hfsplus_bnode_read(). The provided crash trace shows KASAN reporting an 8-byte read past a slab object while handling HFS+ bnode operations, with the stack reaching hfsplus_brec_remove(), __hfsplus_delete_attr(), hfsplus_delete_all_attrs(), and hfsplus_delete_cat() during an unlink path. The supplied CVSS vector indicates a local, low-privilege, no-UI attack path with high confidentiality, integrity, and availability impact if the vulnerable code path is reachable.

Defensive priority

High, with applicability validation first because the supplied advisory metadata is inconsistent.

Recommended defensive actions

  • Apply the vendor-provided fix path listed in the advisory and update to V5.0 or later where applicable.
  • Review whether any deployed systems actually use the affected Linux hfsplus code path or the Siemens product named in the republished advisory.
  • Restrict exposure to removable or untrusted HFS+ media where practical.
  • Monitor for filesystem-related crashes, KASAN-style findings, or unexpected behavior in HFS+ metadata operations on test and production systems.
  • Use the official CISA and Siemens advisory links to confirm scope and remediation before scheduling changes.

Evidence notes

Source item ICSA-26-134-10 (published 2026-05-12, republished 2026-05-14) describes CVE-2025-38714 as a Linux kernel hfsplus_bnode_read() slab-out-of-bounds issue and includes a KASAN crash trace from an unlink-related path. The supplied remediation says to update to V5.0 or later, but the vendor/product metadata in the corpus is low confidence and appears inconsistent with the Linux kernel description, so applicability should be confirmed directly from the official advisories.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-38714 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-38714

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-38714 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38714

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.