PatchSiren cyber security CVE debrief
CVE-2025-39681 Siemens CVE debrief
Published on 2026-05-12 and modified on 2026-05-14, CVE-2025-39681 describes a Linux kernel defect in Hygon x86 boot initialization. A missing resctrl_cpu_detect() call can leave cache-monitoring state uninitialized, leading to a division-by-zero fault during early boot on systems with X86_FEATURE_CQM* support. The impact described in the supplied corpus is availability-only and can prevent affected machines from booting cleanly.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Linux kernel maintainers, distro and embedded Linux operators using Hygon x86 CPUs, and teams responsible for boot reliability on systems that expose resctrl/CQM monitoring features.
Technical summary
The supplied CVE text says resctrl_cpu_detect() was moved into vendor-specific BSP initialization code, but the Hygon path did not include that call. On affected Hygon systems with X86_FEATURE_CQM* support, get_rdt_mon_resources() may read boot_cpu_data.x86_cache_occ_scale before it is initialized and then divide by zero while calculating mon_l3_config. The provided CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local, availability-focused issue.
Defensive priority
Medium. Prioritize patching if you run Linux on Hygon-based x86 hardware with resctrl/CQM features enabled, especially where a boot failure would disrupt production or recovery access.
Recommended defensive actions
- Apply the upstream Linux kernel fix that restores resctrl_cpu_detect() in the Hygon BSP init path.
- Upgrade to a kernel build that includes the resolved patch and verify normal boot on representative affected hardware.
- If you operate Hygon-based systems in production, stage the update and ensure console or out-of-band recovery access before rollout.
- Review whether your deployed kernels and hardware actually expose X86_FEATURE_CQM* and resctrl features so you can scope exposure accurately.
Evidence notes
The supplied source item and CVE description both state that the issue is in the Linux kernel and that the failure is triggered during early boot when Hygon-specific BSP init omits resctrl_cpu_detect(). The corpus also includes a CISA/CSAF advisory record with a Siemens SIMATIC CN 4100 product label and a Siemens remediation pointer, but that product mapping conflicts with the Linux-kernel Hygon description. Because of that mismatch, this debrief treats the CVE text as the authoritative technical description and flags the vendor/product mapping as low confidence and needing review. The supplied data shows no KEV listing.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39681 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39681
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39681 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39681
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.