PatchSiren cyber security CVE debrief
CVE-2025-39788 Siemens CVE debrief
CVE-2025-39788 is a Linux kernel bug in the ufs-exynos storage driver where a left-shift expression can overflow integer width when the number of UTP transfer request slots is 32. On affected systems, the driver may write the wrong value to UTRL_NEXUS_TYPE, and the same fix was applied for UTMRL_NEXUS_TYPE for consistency. The source advisory also notes a UBSAN shift-out-of-bounds warning. The supplied advisory metadata is internally inconsistent about product naming, so the kernel-side vulnerability description should be treated as the primary evidence.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Linux kernel and embedded-platform maintainers who use the ufs-exynos driver path, especially on gs101-class hardware, and security teams tracking the Siemens/CISA advisory feed. Because the provided product metadata does not cleanly match the kernel issue description, asset owners should verify applicability before scheduling remediation.
Technical summary
The issue is an undefined-behavior bug caused by shifting a literal of type int by 32 bits when computing UTRL_NEXUS_TYPE. In the reported gs101 case, that results in an incorrect register value being programmed, with the advisory stating it should be 0xffffffff instead of 0. The fix switches to the BIT() macro so the shift is performed with correct typing and width handling, and the same change is applied to the UTMRL_NEXUS_TYPE write. The advisory references a UBSAN shift-out-of-bounds warning at drivers/ufs/host/ufs-exynos.c:1113:21.
Defensive priority
Medium. The CVSS score in the supplied source is 5.5 with availability impact only, and there is no KEV listing. Prioritize if you operate affected Linux/embedded devices that use the ufs-exynos driver path, but this is not presented as an emergency internet-facing exploitation issue in the source corpus.
Recommended defensive actions
- Update to the fixed version identified in the source advisory: V5.0 or later.
- Verify whether your devices actually use the affected Linux ufs-exynos driver path and gs101-class configuration before prioritizing rollout.
- Check for kernel logs or test output indicating UBSAN shift-out-of-bounds warnings in drivers/ufs/host/ufs-exynos.c.
- Treat the advisory's product mapping cautiously and confirm scope against your own inventory because the provided metadata appears inconsistent.
- Use standard change control and regression testing for storage-driver updates on embedded/industrial devices.
Evidence notes
Primary evidence comes from the CISA CSAF source item and its referenced Siemens ProductCERT advisory. The source description states the shift/typing issue, the gs101 context, the incorrect 0xffffffff-vs-0 register programming detail, and the UBSAN warning. The timeline fields show publication on 2026-05-12 and republication on 2026-05-14. No KEV entry is present. The vendor/product fields in the supplied prompt appear mismatched with the kernel vulnerability text, so this debrief prioritizes the advisory body over the metadata labels.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39788 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39788
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39788 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39788
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.