PatchSiren cyber security CVE debrief
CVE-2025-39823 Siemens CVE debrief
CVE-2025-39823 is a HIGH-severity issue whose source description says the Linux kernel KVM x86 code path used guest-controlled indices in a way that needed speculative-execution hardening. The fix applies array_index_nospec() after bounds checks so guest-provided values are clamped before they can influence speculation. The advisory metadata associates the CVE with Siemens SIMATIC CN 4100 versions before V5.0 and links to Siemens CERT advisory SSA-032379, so defenders should treat this as an advisory-scope update and verify whether their deployment includes the affected code path.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Linux KVM/x86 virtualization maintainers, and operators of Siemens SIMATIC CN 4100 systems covered by the advisory scope, should review this CVE and confirm whether the fixed version applies to their environment.
Technical summary
The supplied description says guest-controlled indices named min and dest_id reached KVM x86 logic. The remediation is to call array_index_nospec() after bounds checks, which reduces the chance that speculative execution can use an out-of-bounds or otherwise attacker-influenced index to leak data through side channels. The source rates the issue CVSS 7.0 HIGH with vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
High. The source assigns a HIGH severity score, and the mitigation is a code-level hardening change that should be verified in any affected deployment as soon as possible.
Recommended defensive actions
- Update to V5.0 or later, per the supplier remediation guidance in the source advisory.
- Confirm whether your environment uses the affected Siemens SIMATIC CN 4100 advisory scope and whether the fixed package/version is available to you.
- Review Linux KVM/x86 virtualization components for the array_index_nospec() hardening change and ensure the patched build is deployed.
- Track the related Siemens CERT and CISA advisory references for any follow-up revisions or product applicability clarifications.
Evidence notes
All substantive claims here are taken from the supplied CISA CSAF source item and its embedded metadata. The source description is about a Linux kernel KVM x86 speculative-execution mitigation, while the advisory metadata maps the CVE to Siemens SIMATIC CN 4100 versions before V5.0 and references Siemens ProductCERT SSA-032379. Because that product mapping and the kernel-focused description do not fully align, the vendor/product scope should be treated cautiously and verified against the official Siemens advisory before making remediation assumptions.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39823 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39823
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39823 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39823
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.