PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-38723 Siemens CVE debrief

CVE-2025-38723 is described in the supplied advisory as a LoongArch Linux kernel BPF tailcall issue where an extra pass of bpf_int_jit_compile() skips JIT context initialization, leaving out_offset at -1 and causing an incorrect negative jump offset in emit_bpf_tail_call. The source states this can produce malformed generated assembly and, in the provided self-test scenario, a watchdog soft lockup. The advisory was published on 2026-05-12 and republished on 2026-05-14.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Linux kernel maintainers, distribution security teams, and operators running LoongArch systems that use eBPF tailcalls or JIT compilation should review this issue. Because the source metadata also maps the advisory to a Siemens SIMATIC CN 4100 product entry, Siemens-focused asset owners should validate applicability against their environment before taking action.

Technical summary

The issue is a jump-offset calculation bug in the LoongArch BPF tailcall path. According to the source, an extra pass of bpf_int_jit_compile() skips JIT context initialization, which skips offset calculation and leaves out_offset = -1. emit_bpf_tail_call then computes jmp_offset as out_offset - cur_offset, resulting in an invalid negative branch offset. The advisory says this can lead to incorrect assembly generation and a soft lockup observed during the tailcall_bpf2bpf_1 selftest. The source lists CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H with a score of 5.5.

Defensive priority

Medium. Prioritize remediation on any LoongArch Linux deployments that rely on eBPF tailcalls or JIT execution, and validate whether the Siemens product mapping in the advisory actually matches your asset inventory.

Recommended defensive actions

  • Apply the vendor or upstream fix that corrects jump offset handling in the LoongArch BPF tailcall path.
  • If you operate LoongArch Linux systems, test relevant eBPF workloads and selftests in a non-production environment after patching.
  • Review whether any production systems use tailcalls or BPF JIT features that could exercise this code path.
  • Monitor kernel watchdog and soft-lockup logs for symptoms during BPF-heavy workloads.
  • If you manage the Siemens product named in the advisory metadata, follow the linked Siemens update guidance and confirm the advisory applies to your deployment.
  • Track the CISA and Siemens advisory pages for any further revisions or clarification.

Evidence notes

The source advisory text states that the vulnerability is resolved in the Linux kernel LoongArch BPF tailcall code path, specifically because an extra pass of bpf_int_jit_compile() skips JIT context initialization and leaves out_offset = -1. It also states that the resulting negative jump offset can lead to incorrect generated assembly and that the provided self-test command reveals a watchdog soft lockup. The source metadata and advisory title reference Siemens SIMATIC CN 4100, but the vulnerability description is kernel/LoongArch-specific, so applicability should be validated carefully. The source lists CVSS 5.5 MEDIUM and was initially published on 2026-05-12, then republished on 2026-05-14.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-38723 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-38723

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-38723 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-38723

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.