PatchSiren cyber security CVE debrief
CVE-2025-39819 Siemens CVE debrief
CVE-2025-39819 is a medium-severity Linux kernel SMB/CIFS issue described in Siemens and CISA advisory material. The reported bug is an inconsistent reference-count cleanup path in smb2_compound_op: when allocation of vars fails and -ENOMEM is returned, the cfile reference may not be dropped as expected, which can lead to resource leakage. The supplied advisory text says the fix adds an extra out cleanup path so the reference handling is always respected, and it treats -ENOMEM as non-recoverable for replay logic.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers responsible for systems covered by the Siemens advisory ICSA-26-134-10 / SSA-032379, especially environments running Siemens SIMATIC CN 4100 versions earlier than 5.0. Linux kernel SMB/CIFS maintainers and defenders monitoring kernel resource leaks should also review it. The vendor mapping in the corpus is low-confidence and should be validated before broad operational assumptions are made.
Technical summary
The source describes a reference-count mismatch in smb2_compound_op. The function comment indicates the cfile reference must be dropped after the call, and the patched path restores that cleanup by adding a goto out label so the cleanup logic is reached consistently. The issue is tied to allocation failure for vars; in that case, existing callers would not otherwise account for the cfile refcount update when -ENOMEM occurs. The advisory also notes that -ENOMEM is not recoverable according to is_replayable_error, so replay handling is skipped.
Defensive priority
Medium. The reported impact is availability-oriented resource leakage rather than direct code execution or integrity compromise, and the CVSS vector in the source is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. Prioritize if the affected Siemens product mapping applies to your environment or if you rely on the impacted Linux SMB code path.
Recommended defensive actions
- Apply the vendor remediation from the advisory: update to V5.0 or later for the affected Siemens product line named in the source corpus.
- Review whether any deployed systems match the advisory scope in ICSA-26-134-10 / SSA-032379 before scheduling maintenance.
- Monitor affected hosts for signs of repeated resource exhaustion or instability associated with SMB/CIFS operations.
- Validate the vendor/product mapping in your asset inventory, because the supplied corpus marks the vendor confidence as low and needs review.
- Track the linked CISA and Siemens advisories for any follow-up revisions or clarifications.
Evidence notes
All substantive statements here are drawn from the supplied source corpus and linked official references. The corpus contains a Linux kernel SMB refcount cleanup description, while the vendor metadata maps the advisory to Siemens SIMATIC CN 4100 vers:intdot/<5.0 with low confidence and needsReview=true. Timing uses the supplied published/modified dates: 2026-05-12 initial publication and 2026-05-14 republication/modify date. No exploit details beyond the advisory summary are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39819 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39819
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39819 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39819
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.