PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39788 Siemens CVE debrief

CVE-2025-39788 is a Linux kernel bug in the ufs-exynos storage driver where a left-shift expression can overflow integer width when the number of UTP transfer request slots is 32. On affected systems, the driver may write the wrong value to UTRL_NEXUS_TYPE, and the same fix was applied for UTMRL_NEXUS_TYPE for consistency. The source advisory also notes a UBSAN shift-out-of-bounds warning. The supplied advisory metadata is internally inconsistent about product naming, so the kernel-side vulnerability description should be treated as the primary evidence.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Linux kernel and embedded-platform maintainers who use the ufs-exynos driver path, especially on gs101-class hardware, and security teams tracking the Siemens/CISA advisory feed. Because the provided product metadata does not cleanly match the kernel issue description, asset owners should verify applicability before scheduling remediation.

Technical summary

The issue is an undefined-behavior bug caused by shifting a literal of type int by 32 bits when computing UTRL_NEXUS_TYPE. In the reported gs101 case, that results in an incorrect register value being programmed, with the advisory stating it should be 0xffffffff instead of 0. The fix switches to the BIT() macro so the shift is performed with correct typing and width handling, and the same change is applied to the UTMRL_NEXUS_TYPE write. The advisory references a UBSAN shift-out-of-bounds warning at drivers/ufs/host/ufs-exynos.c:1113:21.

Defensive priority

Medium. The CVSS score in the supplied source is 5.5 with availability impact only, and there is no KEV listing. Prioritize if you operate affected Linux/embedded devices that use the ufs-exynos driver path, but this is not presented as an emergency internet-facing exploitation issue in the source corpus.

Recommended defensive actions

  • Update to the fixed version identified in the source advisory: V5.0 or later.
  • Verify whether your devices actually use the affected Linux ufs-exynos driver path and gs101-class configuration before prioritizing rollout.
  • Check for kernel logs or test output indicating UBSAN shift-out-of-bounds warnings in drivers/ufs/host/ufs-exynos.c.
  • Treat the advisory's product mapping cautiously and confirm scope against your own inventory because the provided metadata appears inconsistent.
  • Use standard change control and regression testing for storage-driver updates on embedded/industrial devices.

Evidence notes

Primary evidence comes from the CISA CSAF source item and its referenced Siemens ProductCERT advisory. The source description states the shift/typing issue, the gs101 context, the incorrect 0xffffffff-vs-0 register programming detail, and the UBSAN warning. The timeline fields show publication on 2026-05-12 and republication on 2026-05-14. No KEV entry is present. The vendor/product fields in the supplied prompt appear mismatched with the kernel vulnerability text, so this debrief prioritizes the advisory body over the metadata labels.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39788 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39788

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39788 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39788

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.