PatchSiren cyber security CVE debrief
CVE-2025-39743 Siemens CVE debrief
CVE-2025-39743 is a high-severity defect described in the Linux kernel JFS code path. According to the supplied advisory text, inode pages may not be truncated when an inode’s hard-link count is 0, which can trigger a BUGON in clear_inode() because nrpages remains greater than 0. The advisory corpus published by CISA on 2026-05-12 and republished on 2026-05-14 includes a Siemens remediation advising update to V5.0 or later. Note that the vendor/product mapping in the supplied data is low-confidence and should be reviewed against the referenced Siemens advisory material before operational decisions are made.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers responsible for Siemens SIMATIC CN 4100 systems, especially environments running versions earlier than V5.0, as well as teams validating Linux kernel/JFS-related behavior in affected deployments.
Technical summary
The supplied description states that when an inode copied from disk has fileset value AGGR_RESERVED_I and is later evicted with hard-link count 0, its inode pages are not truncated. During clear_inode(), the kernel observes nrpages > 0 and triggers a BUGON. The provided CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a local, hard-to-exploit condition with high impact if reached.
Defensive priority
High. The issue is publicly documented, carries a high CVSS score of 7, and has a vendor remediation path available. Prioritize version verification and patch planning for any potentially affected Siemens SIMATIC CN 4100 deployments.
Recommended defensive actions
- Verify whether any Siemens SIMATIC CN 4100 assets are running versions earlier than V5.0.
- Apply the vendor remediation by updating to V5.0 or later, per the Siemens advisory reference.
- Corroborate the product mapping against the linked Siemens advisory materials before treating this as an exposed asset finding.
- Track this CVE in change-management and maintenance windows for industrial environments where downtime planning is required.
- Use the CISA and Siemens advisory references to confirm affected product scope and any additional operational guidance.
Evidence notes
All statements above are grounded in the supplied CISA CSAF source item and its listed references. The source item says the flaw is resolved in Linux kernel JFS logic and provides a Siemens product remediation, but the vendor/product mapping in the supplied input is explicitly low-confidence and marked for review. Timing context uses the publishedAt/modifiedAt values supplied with the source: initial publication on 2026-05-12 and republication/refresh on 2026-05-14.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39743 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39743
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39743 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39743
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.