PatchSiren cyber security CVE debrief
CVE-2025-39794 Siemens CVE debrief
CVE-2025-39794 is a kernel issue in the Linux ARM Tegra path where normal memcpy is used to write to IRAM, causing KASAN to crash the kernel during boundary checks. In the supplied CISA/Siemens advisory corpus, this issue is mapped to Siemens SIMATIC CN 4100 versions prior to 5.0, with remediation to update to V5.0 or later. The supplied CVSS vector indicates a local, low-privilege attack path with no user interaction and high integrity/availability impact.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
OT/ICS operators using Siemens SIMATIC CN 4100 devices below V5.0, Siemens product owners, Linux kernel maintainers, and defenders responsible for ARM/Tegra-based embedded systems.
Technical summary
The advisory describes a Linux kernel ARM: tegra code path that writes to IRAM using standard memcpy instead of I/O memcpy. According to the source text, KASAN crashes the kernel while checking boundaries with the normal memcpy. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H, which points to a local, low-privilege condition with high integrity and availability impact.
Defensive priority
High for affected Siemens SIMATIC CN 4100 deployments below V5.0, because the vendor remediation is a version update and the scoring shows meaningful local impact to integrity and availability.
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V5.0 or later, per the vendor remediation in the supplied advisory.
- Validate whether any deployed devices are running versions prior to 5.0 and prioritize those systems for patching.
- Review operational procedures for local access control on affected systems, since the CVSS vector indicates local low-privilege conditions.
- Monitor the CISA and Siemens advisories linked in the source corpus for any revisions or additional guidance.
- Use standard ICS defense-in-depth and asset management practices for affected embedded systems.
Evidence notes
Source corpus links the CVE to CISA advisory ICSA-26-134-10 and Siemens ProductCERT advisory SSA-032379. The advisory was initially published on 2026-05-12 and republished by CISA on 2026-05-14. The supplied remediation is to update to V5.0 or later. No KEV entry is present in the supplied corpus. The vendor mapping in the source item is marked low confidence and needs review, so the product association should be treated as advisory-supplied rather than independently confirmed here.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39794 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39794
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39794 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39794
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.