PatchSiren cyber security CVE debrief
CVE-2025-39683 Siemens CVE debrief
CVE-2025-39683 describes a Linux kernel tracing bug in ftrace filter parsing that can lead to a slab out-of-bounds read when an overly long string is written to set_ftrace_filter. The advisory states that trace_get_user can fail on input longer than FTRACE_BUFF_MAX without terminating parser->buffer, allowing later parsing in ftrace_regex_release/ftrace_process_regex to read past the buffer. The sourced advisory package associates the fix with Siemens SIMATIC CN 4100 versions earlier than 5.0 and recommends updating to V5.0 or later.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Administrators and operators responsible for Siemens SIMATIC CN 4100 devices, especially those running versions earlier than 5.0, should prioritize review. Linux kernel maintainers and system teams using tracing/ftrace features should also note the underlying kernel memory-safety issue, particularly in environments where local users can interact with the affected interface.
Technical summary
The source describes an out-of-bounds read in Linux kernel tracing code. If a write to set_ftrace_filter exceeds FTRACE_BUFF_MAX, trace_get_user fails but does not properly terminate parser->buffer. Later cleanup/parsing paths can call strsep on an unterminated buffer, leading to a KASAN-detected slab-out-of-bounds read. The advisory lists CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H, indicating local exploitation conditions and potential confidentiality and availability impact.
Defensive priority
High for affected Siemens SIMATIC CN 4100 deployments and any system exposing the relevant tracing interface to untrusted local users. The vulnerability is locally reachable and rated High (7.1), so patching and exposure review should be handled promptly.
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V5.0 or later, per the sourced remediation guidance.
- Review whether any local users or services can write to set_ftrace_filter or otherwise reach the tracing path.
- Limit access to kernel tracing interfaces to trusted administrative accounts only.
- Monitor the cited Siemens/CISA advisory pages for any follow-on clarification or product scope updates.
- Verify whether the device inventory matches the advisory mapping, since the source corpus ties a Linux kernel issue to a Siemens product advisory package.
Evidence notes
The supplied source corpus is a CISA CSAF advisory republished from Siemens ProductCERT, published 2026-05-12 and modified 2026-05-14. The description explicitly attributes the flaw to Linux kernel tracing code and names the failing condition, the affected parsing path, and the KASAN out-of-bounds read. The remediation field states: update to V5.0 or later version. The vendor/product mapping in the corpus is low-confidence and should be verified because the technical description is kernel-centric while the advisory package is Siemens SIMATIC CN 4100.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39683 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39683
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39683 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39683
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.