PatchSiren cyber security CVE debrief
CVE-2025-39826 Siemens CVE debrief
CVE-2025-39826 is a medium-severity Linux kernel race condition affecting the rose networking code. The issue centers on a non-atomic reference counter in struct rose_neigh that could reach zero while other code paths, including a timer-driven path, still hold a reference. That creates a potential use-after-free condition and an availability impact. The published advisory context is an industrial-control/vendor notice, but the technical flaw itself is in Linux kernel code and was fixed by converting the counter to refcount_t and using atomic hold/put helpers.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of affected Siemens SIMATIC CN 4100 deployments, embedded/OT teams that inherit Linux kernel components from vendor firmware, and Linux kernel/firmware administrators responsible for systems that may include the rose networking subsystem.
Technical summary
The advisory describes a race in the Linux kernel's rose subsystem: struct rose_neigh used an unsigned short 'use' field as a reference count without atomic protection. Under concurrent execution, rose_rt_ioctl() or related paths could reduce the count to zero while a timer or another code path still referenced the object, risking a use-after-free. The fix changes the field to refcount_t and updates callers to use rose_neigh_hold() and rose_neigh_put(), which provide atomic reference counting semantics.
Defensive priority
medium
Recommended defensive actions
- Apply the vendor remediation: update to V5.0 or later, per the Siemens advisory guidance.
- Verify whether any deployed Siemens SIMATIC CN 4100 or other affected images include the vulnerable Linux kernel components.
- Prioritize firmware/OS updates for embedded or OT devices that cannot be independently patched at the application layer.
- Review any monitoring or stability alerts for unexplained crashes that could indicate memory-safety issues in the affected kernel path.
- Track the linked CISA and Siemens advisories for any follow-up revision or product-scope clarification.
Evidence notes
The supplied source item and its references describe a Linux kernel net/rose reference-counting race that can lead to use-after-free. The metadata also maps the advisory to Siemens SIMATIC CN 4100 <5.0, but that product mapping is marked low confidence/needs review in the provided data. Timing context is based on the advisory's published date of 2026-05-12 and modified date of 2026-05-14. The issue is not listed in CISA KEV in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39826 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39826
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39826 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39826
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.