PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39685 Siemens CVE debrief

CVE-2025-39685 describes an input-validation flaw in the Linux kernel’s comedi/pcl726 path where an oversized IRQ selection can trigger an out-of-bounds condition. The source advisory was published on 2026-05-12 and republished on 2026-05-14 by CISA from Siemens ProductCERT material. The advisory recommends updating to V5.0 or later. The source corpus also contains a product-label mismatch: the vulnerability text is clearly Linux-kernel-centric, while the advisory metadata names Siemens SIMATIC CN 4100; that applicability should be reviewed before assuming exposure.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Organizations operating Siemens SIMATIC CN 4100 systems covered by the advisory, and defenders responsible for Linux kernel deployments that include the affected comedi/pcl726 driver path. Because the CVSS vector is local and requires privileges, this is primarily a hardening and patch-management issue for trusted-user or device-management environments.

Technical summary

The advisory text says a reproducer passed an IRQ value of 0x80008000, which was too large and triggered an out-of-bounds condition. The discussed fix is to add interrupt-number validation so users cannot supply an IRQ number that exceeds the valid range. The source also notes a related C-language concern: shifting 1 into bit 31 with `1 << it->options[1]` is undefined behavior, so the upper bound should be constrained or an unsigned shift should be used. The CVSS vector provided by the source is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access, low complexity, low privileges, no user interaction, and high availability impact.

Defensive priority

Medium. The issue is not network-reachable in the provided CVSS vector, but it can still cause service-impacting behavior on systems that expose the affected driver or device configuration path. Patch priority should be elevated where the advisory’s product scope applies or where local device-management interfaces are accessible to lower-privileged users.

Recommended defensive actions

  • Apply the vendor-recommended update to V5.0 or later for the affected product line, per the advisory.
  • Review whether any deployed systems actually include the affected comedi/pcl726 code path or the Siemens product named in the advisory metadata.
  • Limit local access to device-configuration interfaces and other paths that can set IRQ-related options.
  • Validate and sanitize driver- or device-level numeric inputs before they reach bit-shift or IRQ-request logic.
  • Monitor for advisory updates or clarifications because the source corpus contains a Linux-kernel/product-metadata mismatch that affects scoping.

Evidence notes

Source evidence states that an oversized IRQ value (0x80008000) triggered an out-of-bounds condition and that the fix is to add an interrupt-number check. The advisory metadata lists Siemens SIMATIC CN 4100 vers:intdot/<5.0 and recommends updating to V5.0 or later. The same source corpus links to CVE.org, NVD, the CISA ICS advisory page, and Siemens ProductCERT advisory references. Published: 2026-05-12; modified/republished: 2026-05-14. Because the source text and product metadata do not fully align, product applicability should be treated as requiring confirmation.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39685 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39685

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39685 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39685

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.