PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39826 Siemens CVE debrief

CVE-2025-39826 is a medium-severity Linux kernel race condition affecting the rose networking code. The issue centers on a non-atomic reference counter in struct rose_neigh that could reach zero while other code paths, including a timer-driven path, still hold a reference. That creates a potential use-after-free condition and an availability impact. The published advisory context is an industrial-control/vendor notice, but the technical flaw itself is in Linux kernel code and was fixed by converting the counter to refcount_t and using atomic hold/put helpers.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Operators and maintainers of affected Siemens SIMATIC CN 4100 deployments, embedded/OT teams that inherit Linux kernel components from vendor firmware, and Linux kernel/firmware administrators responsible for systems that may include the rose networking subsystem.

Technical summary

The advisory describes a race in the Linux kernel's rose subsystem: struct rose_neigh used an unsigned short 'use' field as a reference count without atomic protection. Under concurrent execution, rose_rt_ioctl() or related paths could reduce the count to zero while a timer or another code path still referenced the object, risking a use-after-free. The fix changes the field to refcount_t and updates callers to use rose_neigh_hold() and rose_neigh_put(), which provide atomic reference counting semantics.

Defensive priority

medium

Recommended defensive actions

  • Apply the vendor remediation: update to V5.0 or later, per the Siemens advisory guidance.
  • Verify whether any deployed Siemens SIMATIC CN 4100 or other affected images include the vulnerable Linux kernel components.
  • Prioritize firmware/OS updates for embedded or OT devices that cannot be independently patched at the application layer.
  • Review any monitoring or stability alerts for unexplained crashes that could indicate memory-safety issues in the affected kernel path.
  • Track the linked CISA and Siemens advisories for any follow-up revision or product-scope clarification.

Evidence notes

The supplied source item and its references describe a Linux kernel net/rose reference-counting race that can lead to use-after-free. The metadata also maps the advisory to Siemens SIMATIC CN 4100 <5.0, but that product mapping is marked low confidence/needs review in the provided data. Timing context is based on the advisory's published date of 2026-05-12 and modified date of 2026-05-14. The issue is not listed in CISA KEV in the supplied enrichment.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39826 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39826

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39826 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39826

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.