PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39776 Siemens CVE debrief

CVE-2025-39776 describes a Linux kernel mm/debug_vm_pgtable test cleanup bug where manually allocated page-table entries are not cleared at destroy_args(). On a debug kernel with CONFIG_DEBUG_VM_PGTABLE=y, stale entries can be reused by a later mm_struct allocation and cause warnings or incorrect memory-management state. The source advisory was published on 2026-05-12 and republished on 2026-05-14 with Siemens ProductCERT material.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Kernel maintainers, downstream distributors, and operators of builds that include CONFIG_DEBUG_VM_PGTABLE or otherwise ship debug-oriented kernel test code should care most. The source advisory metadata maps the issue to Siemens SIMATIC CN 4100 v<5.0, but the vulnerability text itself is Linux-kernel-specific, so affected-product mapping should be verified before prioritizing remediation.

Technical summary

The issue occurs in mm/debug_vm_pgtable when the test harness allocates page-table entries and an mm_struct manually, then exits without calling the *_clear functions in destroy_args(). That leaves stale page-table state behind. If a later process allocates an mm_struct whose pgd lands at the same address, it can encounter those stale entries, leading to kernel warnings such as free_pud_range checks, bad rss-counter state, and negative pgtables_bytes on debug builds. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, consistent with a local availability impact.

Defensive priority

Medium. The issue is confined to a debug/test path, but the advisory shows it can trip real kernel warnings and memory-accounting failures on affected builds. Prioritize if you ship or rely on debug kernels or kernel test configurations; otherwise, track it as a lower-priority hardening fix.

Recommended defensive actions

  • Apply the vendor fix identified in the advisory and update to V5.0 or later where applicable.
  • Backport the kernel cleanup change that clears the manually allocated page-table entries in destroy_args().
  • Verify whether CONFIG_DEBUG_VM_PGTABLE is enabled in any shipped or lab kernels and disable it where it is not needed.
  • Review kernel logs for related mm warnings, especially free_pud_range, bad rss-counter state, or non-zero pgtables_bytes messages after shutdown or test teardown.
  • Confirm the affected-product mapping in the Siemens advisory before using this CVE for product-level exposure tracking.

Evidence notes

The source description says the mm/debug_vm_pgtable test manually allocates page-table entries and an mm_struct, then fails to clear those entries in destroy_args(), leaving stale state that can be hit when another process reuses the same address. The advisory text says this is observed on a debug kernel with CONFIG_DEBUG_VM_PGTABLE=y and includes warning output from free_pud_range, bad rss-counter state, and non-zero pgtables_bytes. The source metadata also supplies the remediation 'Update to V5.0 or later version' and a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. Vendor/product metadata in the supplied corpus is low confidence and should be validated because the narrative is Linux-kernel-specific while the product mapping points to Siemens SIMATIC CN 4100 v<5.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39776 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39776

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39776 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39776

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.