PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39823 Siemens CVE debrief

CVE-2025-39823 is a HIGH-severity issue whose source description says the Linux kernel KVM x86 code path used guest-controlled indices in a way that needed speculative-execution hardening. The fix applies array_index_nospec() after bounds checks so guest-provided values are clamped before they can influence speculation. The advisory metadata associates the CVE with Siemens SIMATIC CN 4100 versions before V5.0 and links to Siemens CERT advisory SSA-032379, so defenders should treat this as an advisory-scope update and verify whether their deployment includes the affected code path.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Linux KVM/x86 virtualization maintainers, and operators of Siemens SIMATIC CN 4100 systems covered by the advisory scope, should review this CVE and confirm whether the fixed version applies to their environment.

Technical summary

The supplied description says guest-controlled indices named min and dest_id reached KVM x86 logic. The remediation is to call array_index_nospec() after bounds checks, which reduces the chance that speculative execution can use an out-of-bounds or otherwise attacker-influenced index to leak data through side channels. The source rates the issue CVSS 7.0 HIGH with vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

Defensive priority

High. The source assigns a HIGH severity score, and the mitigation is a code-level hardening change that should be verified in any affected deployment as soon as possible.

Recommended defensive actions

  • Update to V5.0 or later, per the supplier remediation guidance in the source advisory.
  • Confirm whether your environment uses the affected Siemens SIMATIC CN 4100 advisory scope and whether the fixed package/version is available to you.
  • Review Linux KVM/x86 virtualization components for the array_index_nospec() hardening change and ensure the patched build is deployed.
  • Track the related Siemens CERT and CISA advisory references for any follow-up revisions or product applicability clarifications.

Evidence notes

All substantive claims here are taken from the supplied CISA CSAF source item and its embedded metadata. The source description is about a Linux kernel KVM x86 speculative-execution mitigation, while the advisory metadata maps the CVE to Siemens SIMATIC CN 4100 versions before V5.0 and references Siemens ProductCERT SSA-032379. Because that product mapping and the kernel-focused description do not fully align, the vendor/product scope should be treated cautiously and verified against the official Siemens advisory before making remediation assumptions.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39823 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39823

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39823 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39823

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.