PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39865 Siemens CVE debrief

CVE-2025-39865 describes a Linux kernel NULL pointer dereference in the OP-TEE shared-memory cleanup path. According to the advisory, __optee_disable_shm_cache can receive a NULL result from reg_pair_to_ptr and then pass it to tee_shm_free/tee_shm_put, which can crash the kernel. The supplied crash log shows a kernel paging request and oops during a shutdown/hibernate sequence. CISA’s advisory republished Siemens ProductCERT guidance and lists an update to V5.0 or later as the remediation for the affected Siemens SIMATIC CN 4100 product line.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-28
Original CVE updated
2026-02-25
Advisory published
2026-01-28
Advisory updated
2026-02-25

Who should care

Administrators and operators of Siemens SIMATIC CN 4100 systems, especially those running versions older than 5.0, should treat this as relevant. Linux kernel maintainers and embedded OT teams should also care because the flaw can cause a system-level crash in a privileged kernel path, which may disrupt availability.

Technical summary

The issue is a NULL pointer dereference in tee_shm_put reached from __optee_disable_shm_cache. The source text states that reg_pair_to_ptr(...) may return NULL, but the returned value is then used in tee_shm_free(shm) and tee_shm_put(shm), leading to a crash. The provided panic log and call trace show the fault occurring in tee_shm_put during optee_shutdown/platform_shutdown/device_shutdown, with the failure manifesting as a kernel oops/paging request. The advisory assigns CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

Defensive priority

High for affected deployments. While the advisory indicates local, low-privilege conditions with high attack complexity, the impact includes kernel crash and service interruption in an OT-adjacent product context. Availability loss in industrial or embedded environments can have outsized operational impact, so remediation should be prioritized on exposed systems.

Recommended defensive actions

  • Update Siemens SIMATIC CN 4100 to V5.0 or later, per the vendor remediation guidance.
  • Validate whether your deployed product/version mapping matches the advisory before and after remediation, since the provided product metadata is low-confidence and marked for review.
  • Inventory systems that use the affected Linux kernel/OP-TEE path and determine whether shutdown, hibernate, or OP-TEE cache-disable workflows are present.
  • Plan maintenance windows for updates because the observed failure occurs in a system power-management path that may be operationally sensitive.
  • Monitor vendor and CISA advisory updates for any clarifications, especially if your environment depends on repackaged firmware or downstream kernel builds.
  • Use standard OT defensive practices to reduce the blast radius of a crash-prone component, including segmentation, least privilege, and recovery planning.

Evidence notes

The debrief is based only on the supplied CISA CSAF source item and its cited official references. The source text explicitly states: a NULL pointer may be returned by reg_pair_to_ptr, tee_shm_put is called on that value, and the result is a crash. The embedded panic log and call trace corroborate kernel oops behavior in tee_shm_put. CISA’s advisory metadata lists the affected product as Siemens SIMATIC CN 4100 vers:intdot/<5.0 and the remediation as update to V5.0 or later. The CVSS vector provided in the source is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39865 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39865

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39865 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39865

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.