PatchSiren

siemens CVE debriefs · Page 39

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38167

CVE-2025-38167 is a Linux kernel ntfs3 null-handling flaw that Siemens and CISA map to affected SIMATIC S7-1500 CPU family products with an additional GNU/Linux subsystem. The advisory rates it CVSS 5.5 (MEDIUM) and indicates a local, low-privilege availability impact. Siemens states that no fix is currently available, so access restriction and trusted-software controls are the main defenses.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38124

CVE-2025-38124 is a Linux kernel networking issue tied to UDP GSO segmentation after pulling from a frag_list. In the Siemens/CISA advisory context, it affects SIMATIC S7-1500 CPU family products that include an additional GNU/Linux subsystem. The source advisory lists mitigations only and states that no fix is currently available. Because the CVSS vector emphasizes local access and high availability impa [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38100

CVE-2025-38100 is a Linux kernel flaw described in Siemens/CISA advisory ICSA-25-162-05. A TIF_IO_BITMAP state inconsistency can lead to a NULL pointer dereference in tss_update_io_bitmap(), creating an availability impact that is rated medium severity in the supplied record. The advisory ties exposure to affected SIMATIC S7-1500 CPU family products and states that no fix was available in the supplied material.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38083

CVE-2025-38083 is a race condition in the Linux kernel PRIO scheduler path that Siemens and CISA document in advisory ICSA-25-162-05 for affected SIMATIC S7-1500 CPU products. The issue can underflow a parent queue length and therefore create an availability risk. The supplied advisory data states that no fix was available at publication, so exposure reduction depends on access control and trusted-source [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-38079

CVE-2025-38079 is a high-severity Linux kernel memory-safety issue that Siemens surfaced in its SIMATIC S7-1500 CPU family advisory. The flaw is in crypto: algif_hash, where a failed crypto_ahash_import path during accept(2) with MSG_MORE set can free sk2 twice, leading to slab-use-after-free behavior. The CISA CSAF advisory was published on 2025-06-10 and was most recently republished on 2026-05-14. Siem [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38067

CVE-2025-38067 describes a Linux kernel rseq registration flaw that can trigger a segfault when rseq_cs is non-zero. In the supplied Siemens/CISA advisory context, the issue is mapped to specific SIMATIC S7-1500 CPU variants and the advisory lists no fix at the time of publication, only compensating mitigations.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38063

CVE-2025-38063 is a Linux kernel device-mapper issue that can cause unnecessary I/O throttling when a flush request is processed. Siemens’ advisory maps the issue to several SIMATIC S7-1500 CPU models with an additional GNU/Linux subsystem, and the source material notes that no fix was available at publication time.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-38058

CVE-2025-38058 was published on 2025-06-10 and last updated on 2026-05-14. The advisory describes a race in Linux kernel __legitimize_mnt() where a check for MNT_SYNC_UMOUNT occurs outside mount_lock. In a narrow timing window around umount(2), that can let a mount reference count be raised after the victim has already been verified as not busy, which prevents the quiet undo path and can force a full mntp [truncated]

LOW Siemens CVE published 2025-06-10

CVE-2025-3198

CVE-2025-3198 is a low-severity, locally exploitable memory leak described in GNU Binutils 2.43/2.44, specifically in objdump's display_info path. In Siemens' advisory context, it is associated with several SIMATIC S7-1500 CPU variants, and the source states that no fix is currently available for the affected products. Because the issue requires local access and the source notes publicly disclosed exploit [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-31115

CVE-2025-31115 is a high-severity flaw in XZ Utils’ liblzma multithreaded .xz decoder. The supplied Siemens advisory maps the issue to specific SIMATIC S7-1500 CPU variants and states that invalid input can trigger a crash, heap use-after-free, or a write based on a null pointer plus offset. Siemens’ advisory says no fix is currently available for the listed products, so operators should rely on compensat [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21865

CVE-2025-21865 is a local-attack, availability-impact vulnerability tied by Siemens and CISA to select SIMATIC S7-1500 CPU models that include a GNU/Linux subsystem. The underlying issue described in the CVE record is a kernel teardown bug in gtp_net_exit_batch_rtnl() where device deletion can be triggered twice during exit_batch_rtnl(), creating a list-corruption condition. Siemens’ advisory and the CISA [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21864

CVE-2025-21864 is a Linux kernel availability issue affecting Siemens SIMATIC S7-1500 CPU 1518 MFP-family products in the supplied advisory. The reported bug can leave a secpath-linked reference to xfrm_state attached to an skb during deferred cleanup, so the reference is still present when a network namespace is deleted. In the source description, this can trigger a WARN in xfrm6_tunnel_net_exit during T [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21862

CVE-2025-21862 is a medium-severity local availability issue described in Siemens' advisory for the SIMATIC S7-1500 CPU family. The flaw is in the Linux drop_monitor path: when drop_monitor is built as a kernel module, a NET_DM_CMD_START netlink message can arrive during module loading and reach net_dm_monitor_start() before its spinlock is initialized, creating a denial-of-service risk. Siemens' advisory [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21848

CVE-2025-21848 is a null pointer dereference issue in the Linux kernel nfp BPF path, where nfp_bpf_cmsg_alloc() should check the return value of nfp_app_ctrl_msg_alloc(). Siemens’ advisory maps this issue to several SIMATIC S7-1500 CPU family products and states that no fix is currently available. The practical concern in the supplied advisory is availability impact rather than confidentiality or integrity loss.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21796

The supplied advisory data ties CVE-2025-21796 to five Siemens SIMATIC/SIPLUS S7-1500 CPU variants and describes a local availability issue in nfsd ACL handling. Siemens/CISA rate it CVSS 5.5 (medium) with high availability impact, no confidentiality or integrity impact, and no current fix available. For OT environments, the practical priority is to reduce exposure of the GNU/Linux subsystem and limit who [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21795

CVE-2025-21795 is an availability issue in the NFSD shutdown path that can leave nfsd4_shutdown_callback waiting when an nfs4_client is in courtesy state. In Siemens’ advisory for the SIMATIC S7-1500 CPU family, the result is a prolonged hang of roughly 15 minutes until TCP indicates the connection was dropped. CISA republishes the Siemens advisory for the affected CPU variants, and the source set indicat [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21767

CVE-2025-21767 is a Linux kernel bug called out in Siemens/CISA advisory ICSA-25-162-05 for specific Siemens SIMATIC S7-1500 CPU 1518-* MFP and SIPLUS variants. The issue is tied to PREEMPT_RT behavior in the clocksource watchdog path: clocksource_verify_choose_cpus() can call get_random_u32() while preemption is disabled, which may hit sleeping locks and trigger a kernel BUG. The published advisory rates [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21766

CVE-2025-21766 is a medium-severity availability issue affecting select Siemens SIMATIC S7-1500 CPU 1518 MFP variants. The advisory ties the risk to the device’s additional GNU/Linux subsystem, and Siemens/CISA note that no fix is currently available. The practical takeaway is to restrict subsystem access and limit use to trusted software sources while monitoring for vendor updates.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21765

CVE-2025-21765 is a medium-severity availability issue tied to IPv6 handling in ip6_default_advmss(). The source description says the function needs RCU protection so the net structure it reads does not disappear. In the Siemens/CISA advisory corpus, the issue is mapped to five Siemens SIMATIC S7-1500 CPU MFP product variants, with no fix available in the cited advisory and compensating mitigations instead.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21758

CVE-2025-21758 is a medium-severity issue described as missing RCU protection in the IPv6 multicast path around mld_newpack(). In the Siemens/CISA advisory context, it applies to specific SIMATIC S7-1500 CPU variants that include an additional GNU/Linux subsystem, with no fix available at publication time.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21756

CVE-2025-21756 is a medium-severity local availability issue associated in Siemens' CSAF advisory with specific SIMATIC S7-1500 CPU MFP and SIPLUS CPU variants. The CVE description points to a vsock binding-preservation flaw, while Siemens' remediation notes say no fix is currently available, so defenders should rely on access restriction and trusted-source controls for the affected GNU/Linux subsystem.

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21745

CVE-2025-21745 is a Linux kernel issue that Siemens and CISA map to the SIMATIC S7-1500 CPU family. The flaw is a refcount leakage in blk-cgroup code: blkcg_fill_root_iostats() iterates through block_class devices but does not end the iteration with class_dev_iter_exit(), which can leak the class subsystem reference count. The advisory characterizes the issue as an availability problem with local attack c [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21728

CVE-2025-21728 is a medium-severity availability issue affecting Siemens SIMATIC S7-1500 CPU MFP variants that include an additional GNU/Linux subsystem. The source advisory maps the issue to Linux BPF signal handling: if a non-preemptible BPF program uses bpf_send_signal(), the call can sleep and trigger problems in that execution context. Siemens/CISA list no fix at publication time, so defenders should [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21724

CVE-2025-21724 is a local memory-safety issue in the Linux iommufd/iova_bitmap code path that Siemens included in its SIMATIC S7-1500 CPU family advisory. The problem is a shift-out-of-bounds in iova_bitmap_offset_to_index(): the expression shifts the integer literal 1 by bitmap->mapped.pgshift, and when pgshift is greater than 31 on a typical 32-bit int, the shift becomes undefined behavior. CISA’s CSAF [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21712

CVE-2025-21712 is a Siemens-disclosed availability issue affecting several SIMATIC S7-1500 CPU family products that include an additional GNU/Linux subsystem. The advisory describes a Linux md/md-bitmap flaw where bitmap_get_stats() can be called after a bitmap is destroyed or before it is fully initialized, which can crash the kernel. Siemens states there is currently no fix available and recommends rest [truncated]

HIGH Siemens CVE published 2025-06-10

CVE-2025-21702

CVE-2025-21702 is a high-severity Linux kernel queue-management issue described in Siemens and CISA advisories for the SIMATIC S7-1500 CPU family. The supplied advisory text says a pfifo_tail_enqueue() edge case can increase queue length even when sch->limit is 0 and the queue is empty, violating parent/child qlen accounting. Siemens/CISA state the issue can be used for user-to-kernel privilege escalation [truncated]

MEDIUM Siemens CVE published 2025-06-10

CVE-2025-21701

CVE-2025-21701 is a Siemens advisory for several SIMATIC S7-1500 CPU 1518/1518F MFP variants. The issue is described as a race in network device teardown and ethnl operations that can result in use of destroyed locks, creating an availability risk rather than a confidentiality or integrity issue. The published guidance states that no fix was available at the time of disclosure and relies on compensating controls.

LOW Siemens CVE published 2025-06-10

CVE-2025-11840

CVE-2025-11840 is a locally exploitable out-of-bounds read condition tied to vfinfo in ldmisc.c from GNU Binutils 2.45, as described in the advisory corpus. Siemens’ CSAF advisory maps the issue to five SIMATIC S7-1500 CPU family products and states that the attack can only be executed locally, with public exploit availability noted in the CVE description. The advisory set was first published on 2025-06-1 [truncated]

LOW Siemens CVE published 2025-06-10

CVE-2025-11839

CVE-2025-11839 is mapped in the supplied CISA/Siemens advisory to the Siemens SIMATIC S7-1500 CPU family. The advisory text says the issue is a local flaw and the CVE description reports an unchecked return value in tg_tag_type within prdbg.c, with a public exploit reportedly released. Siemens/CISA state that no fix is currently available and advise compensating access controls.

LOW Siemens CVE published 2025-06-10

CVE-2025-11495

CVE-2025-11495 is a publicly disclosed, local heap-based buffer overflow in GNU Binutils 2.45. Siemens’ CSAF advisory maps the issue to SIMATIC S7-1500 CPU 1518-4/1518F-4 PN/DP MFP variants and advises restricting access to the device’s additional GNU/Linux subsystem while no fix is listed in the supplied advisory corpus.