PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39742 Siemens CVE debrief

CVE-2025-39742 describes a Linux kernel RDMA issue in hfi1 where find_hw_thread_mask() could divide the number of online CPUs by num_core_siblings before verifying that the divisor is nonzero. That ordering creates a possible divide-by-zero runtime error and an availability impact consistent with the published CVSS 5.5 (MEDIUM) rating. The vendor guidance in the advisory is to update to V5.0 or later. The advisory was published by CISA on 2026-05-12 and republished on 2026-05-14 from Siemens ProductCERT material. Because the source metadata also lists Siemens SIMATIC CN 4100 and a low-confidence vendor mapping, this record should be read with caution: the technical defect text is clearly Linux-kernel based, while the product mapping in the advisory needs review.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Operators of systems covered by the Siemens/CISA advisory, especially environments using Siemens SIMATIC CN 4100 as identified in the source material, and teams responsible for Linux kernel maintenance, RDMA-enabled systems, and availability-sensitive infrastructure.

Technical summary

The flaw is a classic divide-by-zero condition (CWE-369). In find_hw_thread_mask(), the code divides by num_core_siblings and only later checks whether that value is zero. The fix moves the zero check ahead of the division, preventing a runtime fault and removing an unnecessary indentation level. The published CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates local access, low privileges, no user interaction, and high availability impact.

Defensive priority

Medium

Recommended defensive actions

  • Apply the vendor remediation: update to V5.0 or later, as directed in the advisory.
  • Review systems that include the affected Linux kernel RDMA hfi1 path and confirm whether the advisory applies to your deployment.
  • Prioritize patching on availability-sensitive hosts first, since the impact is denial of service rather than confidentiality or integrity loss.
  • Verify asset inventories against the Siemens advisory references before treating the product mapping as authoritative, because the source metadata is marked low confidence and needs review.
  • Track the CISA advisory and Siemens ProductCERT references for any revision updates or clarification.

Evidence notes

Primary evidence comes from the CISA CSAF source item for ICSA-26-134-10 and the embedded advisory description, which explicitly states that find_hw_thread_mask() divided by num_core_siblings before checking it for zero. The source also lists the remediation as updating to V5.0 or later. The official CVSS vector and CWE-369 reference support the availability-focused, divide-by-zero characterization. The advisory metadata contains a low-confidence product mapping (Siemens SIMATIC CN 4100) that should be treated cautiously.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39742 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39742

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39742 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39742

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.