PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39743 Siemens CVE debrief

CVE-2025-39743 is a high-severity defect described in the Linux kernel JFS code path. According to the supplied advisory text, inode pages may not be truncated when an inode’s hard-link count is 0, which can trigger a BUGON in clear_inode() because nrpages remains greater than 0. The advisory corpus published by CISA on 2026-05-12 and republished on 2026-05-14 includes a Siemens remediation advising update to V5.0 or later. Note that the vendor/product mapping in the supplied data is low-confidence and should be reviewed against the referenced Siemens advisory material before operational decisions are made.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Operators and maintainers responsible for Siemens SIMATIC CN 4100 systems, especially environments running versions earlier than V5.0, as well as teams validating Linux kernel/JFS-related behavior in affected deployments.

Technical summary

The supplied description states that when an inode copied from disk has fileset value AGGR_RESERVED_I and is later evicted with hard-link count 0, its inode pages are not truncated. During clear_inode(), the kernel observes nrpages > 0 and triggers a BUGON. The provided CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a local, hard-to-exploit condition with high impact if reached.

Defensive priority

High. The issue is publicly documented, carries a high CVSS score of 7, and has a vendor remediation path available. Prioritize version verification and patch planning for any potentially affected Siemens SIMATIC CN 4100 deployments.

Recommended defensive actions

  • Verify whether any Siemens SIMATIC CN 4100 assets are running versions earlier than V5.0.
  • Apply the vendor remediation by updating to V5.0 or later, per the Siemens advisory reference.
  • Corroborate the product mapping against the linked Siemens advisory materials before treating this as an exposed asset finding.
  • Track this CVE in change-management and maintenance windows for industrial environments where downtime planning is required.
  • Use the CISA and Siemens advisory references to confirm affected product scope and any additional operational guidance.

Evidence notes

All statements above are grounded in the supplied CISA CSAF source item and its listed references. The source item says the flaw is resolved in Linux kernel JFS logic and provides a Siemens product remediation, but the vendor/product mapping in the supplied input is explicitly low-confidence and marked for review. Timing context uses the publishedAt/modifiedAt values supplied with the source: initial publication on 2026-05-12 and republication/refresh on 2026-05-14.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39743 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39743

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39743 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39743

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.