PatchSiren cyber security CVE debrief
CVE-2025-38723 Siemens CVE debrief
CVE-2025-38723 is described in the supplied advisory as a LoongArch Linux kernel BPF tailcall issue where an extra pass of bpf_int_jit_compile() skips JIT context initialization, leaving out_offset at -1 and causing an incorrect negative jump offset in emit_bpf_tail_call. The source states this can produce malformed generated assembly and, in the provided self-test scenario, a watchdog soft lockup. The advisory was published on 2026-05-12 and republished on 2026-05-14.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Linux kernel maintainers, distribution security teams, and operators running LoongArch systems that use eBPF tailcalls or JIT compilation should review this issue. Because the source metadata also maps the advisory to a Siemens SIMATIC CN 4100 product entry, Siemens-focused asset owners should validate applicability against their environment before taking action.
Technical summary
The issue is a jump-offset calculation bug in the LoongArch BPF tailcall path. According to the source, an extra pass of bpf_int_jit_compile() skips JIT context initialization, which skips offset calculation and leaves out_offset = -1. emit_bpf_tail_call then computes jmp_offset as out_offset - cur_offset, resulting in an invalid negative branch offset. The advisory says this can lead to incorrect assembly generation and a soft lockup observed during the tailcall_bpf2bpf_1 selftest. The source lists CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H with a score of 5.5.
Defensive priority
Medium. Prioritize remediation on any LoongArch Linux deployments that rely on eBPF tailcalls or JIT execution, and validate whether the Siemens product mapping in the advisory actually matches your asset inventory.
Recommended defensive actions
- Apply the vendor or upstream fix that corrects jump offset handling in the LoongArch BPF tailcall path.
- If you operate LoongArch Linux systems, test relevant eBPF workloads and selftests in a non-production environment after patching.
- Review whether any production systems use tailcalls or BPF JIT features that could exercise this code path.
- Monitor kernel watchdog and soft-lockup logs for symptoms during BPF-heavy workloads.
- If you manage the Siemens product named in the advisory metadata, follow the linked Siemens update guidance and confirm the advisory applies to your deployment.
- Track the CISA and Siemens advisory pages for any further revisions or clarification.
Evidence notes
The source advisory text states that the vulnerability is resolved in the Linux kernel LoongArch BPF tailcall code path, specifically because an extra pass of bpf_int_jit_compile() skips JIT context initialization and leaves out_offset = -1. It also states that the resulting negative jump offset can lead to incorrect generated assembly and that the provided self-test command reveals a watchdog soft lockup. The source metadata and advisory title reference Siemens SIMATIC CN 4100, but the vulnerability description is kernel/LoongArch-specific, so applicability should be validated carefully. The source lists CVSS 5.5 MEDIUM and was initially published on 2026-05-12, then republished on 2026-05-14.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-38723 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-38723
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-38723 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38723
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.