PatchSiren cyber security CVE debrief
CVE-2025-39685 Siemens CVE debrief
CVE-2025-39685 describes an input-validation flaw in the Linux kernel’s comedi/pcl726 path where an oversized IRQ selection can trigger an out-of-bounds condition. The source advisory was published on 2026-05-12 and republished on 2026-05-14 by CISA from Siemens ProductCERT material. The advisory recommends updating to V5.0 or later. The source corpus also contains a product-label mismatch: the vulnerability text is clearly Linux-kernel-centric, while the advisory metadata names Siemens SIMATIC CN 4100; that applicability should be reviewed before assuming exposure.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Organizations operating Siemens SIMATIC CN 4100 systems covered by the advisory, and defenders responsible for Linux kernel deployments that include the affected comedi/pcl726 driver path. Because the CVSS vector is local and requires privileges, this is primarily a hardening and patch-management issue for trusted-user or device-management environments.
Technical summary
The advisory text says a reproducer passed an IRQ value of 0x80008000, which was too large and triggered an out-of-bounds condition. The discussed fix is to add interrupt-number validation so users cannot supply an IRQ number that exceeds the valid range. The source also notes a related C-language concern: shifting 1 into bit 31 with `1 << it->options[1]` is undefined behavior, so the upper bound should be constrained or an unsigned shift should be used. The CVSS vector provided by the source is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access, low complexity, low privileges, no user interaction, and high availability impact.
Defensive priority
Medium. The issue is not network-reachable in the provided CVSS vector, but it can still cause service-impacting behavior on systems that expose the affected driver or device configuration path. Patch priority should be elevated where the advisory’s product scope applies or where local device-management interfaces are accessible to lower-privileged users.
Recommended defensive actions
- Apply the vendor-recommended update to V5.0 or later for the affected product line, per the advisory.
- Review whether any deployed systems actually include the affected comedi/pcl726 code path or the Siemens product named in the advisory metadata.
- Limit local access to device-configuration interfaces and other paths that can set IRQ-related options.
- Validate and sanitize driver- or device-level numeric inputs before they reach bit-shift or IRQ-request logic.
- Monitor for advisory updates or clarifications because the source corpus contains a Linux-kernel/product-metadata mismatch that affects scoping.
Evidence notes
Source evidence states that an oversized IRQ value (0x80008000) triggered an out-of-bounds condition and that the fix is to add an interrupt-number check. The advisory metadata lists Siemens SIMATIC CN 4100 vers:intdot/<5.0 and recommends updating to V5.0 or later. The same source corpus links to CVE.org, NVD, the CISA ICS advisory page, and Siemens ProductCERT advisory references. Published: 2026-05-12; modified/republished: 2026-05-14. Because the source text and product metadata do not fully align, product applicability should be treated as requiring confirmation.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39685 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39685
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39685 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39685
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.