PatchSiren cyber security CVE debrief
CVE-2025-39776 Siemens CVE debrief
CVE-2025-39776 describes a Linux kernel mm/debug_vm_pgtable test cleanup bug where manually allocated page-table entries are not cleared at destroy_args(). On a debug kernel with CONFIG_DEBUG_VM_PGTABLE=y, stale entries can be reused by a later mm_struct allocation and cause warnings or incorrect memory-management state. The source advisory was published on 2026-05-12 and republished on 2026-05-14 with Siemens ProductCERT material.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Kernel maintainers, downstream distributors, and operators of builds that include CONFIG_DEBUG_VM_PGTABLE or otherwise ship debug-oriented kernel test code should care most. The source advisory metadata maps the issue to Siemens SIMATIC CN 4100 v<5.0, but the vulnerability text itself is Linux-kernel-specific, so affected-product mapping should be verified before prioritizing remediation.
Technical summary
The issue occurs in mm/debug_vm_pgtable when the test harness allocates page-table entries and an mm_struct manually, then exits without calling the *_clear functions in destroy_args(). That leaves stale page-table state behind. If a later process allocates an mm_struct whose pgd lands at the same address, it can encounter those stale entries, leading to kernel warnings such as free_pud_range checks, bad rss-counter state, and negative pgtables_bytes on debug builds. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, consistent with a local availability impact.
Defensive priority
Medium. The issue is confined to a debug/test path, but the advisory shows it can trip real kernel warnings and memory-accounting failures on affected builds. Prioritize if you ship or rely on debug kernels or kernel test configurations; otherwise, track it as a lower-priority hardening fix.
Recommended defensive actions
- Apply the vendor fix identified in the advisory and update to V5.0 or later where applicable.
- Backport the kernel cleanup change that clears the manually allocated page-table entries in destroy_args().
- Verify whether CONFIG_DEBUG_VM_PGTABLE is enabled in any shipped or lab kernels and disable it where it is not needed.
- Review kernel logs for related mm warnings, especially free_pud_range, bad rss-counter state, or non-zero pgtables_bytes messages after shutdown or test teardown.
- Confirm the affected-product mapping in the Siemens advisory before using this CVE for product-level exposure tracking.
Evidence notes
The source description says the mm/debug_vm_pgtable test manually allocates page-table entries and an mm_struct, then fails to clear those entries in destroy_args(), leaving stale state that can be hit when another process reuses the same address. The advisory text says this is observed on a debug kernel with CONFIG_DEBUG_VM_PGTABLE=y and includes warning output from free_pud_range, bad rss-counter state, and non-zero pgtables_bytes. The source metadata also supplies the remediation 'Update to V5.0 or later version' and a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. Vendor/product metadata in the supplied corpus is low confidence and should be validated because the narrative is Linux-kernel-specific while the product mapping points to Siemens SIMATIC CN 4100 v<5.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39776 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39776
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39776 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39776
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.