PatchSiren cyber security CVE debrief
CVE-2025-39808 Siemens CVE debrief
CVE-2025-39808 describes a Linux kernel HID issue in ntrig_report_version() where a missing null check can let hid_to_usb_dev() operate on an invalid USB parent path and trigger a page fault. The advisory source maps this to Siemens SIMATIC CN 4100 v<5.0 and recommends updating to V5.0 or later. Published by CISA on 2026-05-12 and republished on 2026-05-14, it is best treated as a medium-priority availability fix.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Siemens SIMATIC CN 4100 operators, OT/ICS asset owners, and teams responsible for Linux-based device firmware or HID/USB input handling should review this advisory. Security teams should also verify whether any deployed systems use the affected component path described in the advisory and whether version V5.0 or later is installed.
Technical summary
The vulnerability text says that in ntrig_report_version(), a descriptor path sent to /dev/uhid can leave hdev->dev.parent->parent null. When hid_to_usb_dev(hdev) is then used by usb_rcvctrlpipe(), it may dereference an invalid address and cause a page fault. The resolved fix adds a null check before calling hid_to_usb_dev().
Defensive priority
Moderate. Prioritize this as a stability and availability fix, especially on systems that may process untrusted HID descriptors or rely on the affected kernel path. The stated remediation is to update to V5.0 or later.
Recommended defensive actions
- Update affected Siemens SIMATIC CN 4100 systems to V5.0 or later, per the advisory remediation.
- Confirm whether your deployment uses the Linux kernel HID path referenced by ntrig_report_version() and document exposure.
- Review logs and crash reports for kernel page faults or USB/HID handling errors around the affected component.
- Coordinate patching during a maintenance window if the device is production OT/ICS infrastructure.
- Validate vendor guidance from Siemens and CISA before making changes in safety- or uptime-sensitive environments.
Evidence notes
Source timing is based on the advisory publication date of 2026-05-12 and CISA republication on 2026-05-14, not on generation time. The source advisory (ICSA-26-134-10) and Siemens ProductCERT reference both describe the Linux kernel HID/ntrig page-fault condition and the remediation to update to V5.0 or later. The vendor/product mapping in the supplied data is low confidence and appears inconsistent with the vulnerability text, so it should be reviewed before operational use.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39808 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39808
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39808 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39808
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.