PatchSiren

siemens CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2026-05-12

CVE-2025-47219

CVE-2025-47219 is a memory-safety issue described in the source corpus as a heap buffer read past the end while GStreamer’s isomp4 plugin parses an MP4 file. The advisory metadata also maps it to Siemens SIMATIC CN 4100 with low confidence, so product applicability should be confirmed before acting on the remediation.

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-43368

CVE-2025-43368 describes a use-after-free condition that was addressed with improved memory management. According to the advisory text in the supplied corpus, maliciously crafted web content may trigger an unexpected Safari crash, and the fix is included in Safari 26, iOS 26, iPadOS 26, and macOS Tahoe 26. The reported CVSS score is 4.3 (medium), reflecting a network-reachable issue that requires user int [truncated]

CRITICAL Siemens CVE published 2026-05-12

CVE-2025-40949

CVE-2025-40949 affects Siemens RUGGEDCOM ROX devices exposed through the Web UI Scheduler function. According to the CISA-published advisory, user-supplied input is not properly sanitized, which can let commands be injected into the task scheduling backend. The impact is severe: an authenticated remote attacker could execute arbitrary commands with root privileges on the underlying operating system. Sieme [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-40948

CVE-2025-40948 is a medium-severity issue in Siemens RUGGEDCOM ROX web server JSON-RPC handling. CISA’s advisory says affected devices fail to properly validate input, which could let an authenticated remote attacker read arbitrary files from the underlying operating system filesystem with root privileges. The supplied remediation is to update to V2.17.1 or later.

HIGH Siemens CVE published 2026-05-12

CVE-2025-40947

CVE-2025-40947 affects multiple Siemens RUGGEDCOM ROX devices when user-supplied input is not properly sanitized during feature key installation. According to the advisory, an authenticated remote attacker could inject arbitrary commands and achieve remote code execution with root privileges on the underlying operating system. Siemens and CISA list an update to V2.17.1 or later as the fix.

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-40300

CVE-2025-40300 is described in the supplied advisory text as a Linux x86 VMSCAPE mitigation issue: after a VMexit, the kernel conditionally issues an IBPB before returning to userspace so that poisoned branch predictors from a guest do not affect the userspace hypervisor path. The source notes that existing mitigations already protect kernel/KVM from a malicious guest, but userspace can still be exposed. [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39857

CVE-2025-39857 is a Linux kernel NULL pointer dereference in the SMC/RDMA path, documented by CISA and Siemens ProductCERT. The advisory says the issue can be triggered when a software RoCE device is used and the kernel reaches smc_ib_is_sg_need_sync() with ibdev->dma_device set to null, which can crash the system; Siemens recommends updating SIMATIC CN 4100 to V5.0 or later.

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39849

CVE-2025-39849 is a medium-severity memory-corruption issue described as a missing SSID-length bounds check in Linux kernel cfg80211 connection-result handling. The supplied advisory corpus maps the issue to Siemens SIMATIC CN 4100 versions earlier than 5.0 and recommends updating to V5.0 or later.

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39848

CVE-2025-39848 is a medium-severity denial-of-service issue tied to Linux kernel AX.25 packet handling. According to the advisory text, ax25_kiss_rcv() can queue or mangle a shared skb without unsharing it first, which can leave skb->dev NULL and trigger a crash in __netif_receive_skb_core(). The source advisory maps the issue to Siemens SIMATIC CN 4100 versions earlier than V5.0 and recommends updating t [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39847

CVE-2025-39847 describes a Linux kernel PPP memory leak in pad_compress_skb(). If alloc_skb() fails, the function can return NULL before the old skb reference is safely preserved, so the caller’s cleanup path no longer frees the original buffer. The published fix changes the ownership flow to match realloc-style behavior: only release the old skb after the new allocation and compression succeed, and keep [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39845

CVE-2025-39845 is a Linux kernel x86/mm/64 page-table synchronization flaw that can trigger boot-time page faults or vmemmap crashes on systems using 4-level paging and persistent memory. In the supplied advisory corpus, CISA republishes Siemens ProductCERT advisory SSA-032379 and maps the issue to Siemens SIMATIC CN 4100 versions earlier than 5.0, with a published CVSS score of 5.5/Medium. The issue is p [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39844

CVE-2025-39844 describes a Linux kernel memory-management flaw that can cause an availability-impacting boot failure. According to the advisory text, the problem appears when the vmemmap region spans two PGD entries and the optimized compound-page path does not synchronize top-level page tables for all tasks. In affected configurations, that can produce a supervisor-mode page fault during vmemmap initiali [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39843

CVE-2025-39843 describes a Linux kernel locking flaw that can trigger spinlock recursion and a deadlock/OOPS during timer and slab allocation activity. In the supplied Siemens/CISA advisory, the issue is tied to Siemens SIMATIC CN 4100 versions earlier than 5.0 and is rated HIGH. The defensive takeaway is straightforward: affected deployments should be identified and updated to the vendor-fixed release.

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39842

CVE-2025-39842 is a Linux kernel ocfs2 issue that can lead to a null-pointer dereference during volume dismount after journal shutdown has already occurred. The advisory states that osb->journal should be NULL at that point, and that adding checks before releasing the journal inode prevents the failure path. The stated impact is availability-only and the CVSS vector indicates local access with low privileges.

HIGH Siemens CVE published 2026-05-12

CVE-2025-39838

CVE-2025-39838 describes a NULL pointer dereference in Linux kernel CIFS UTF-16 conversion. According to the advisory text, NULL can flow into cifs_strndup_to_utf16 and then into cifs_local_to_utf16_bytes, where a dereference of '*from' can crash the system. The documented fix adds a NULL check and returns early. The advisory was published by CISA on 2026-05-12 and republished on 2026-05-14 with Siemens P [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39835

CISA published this advisory on 2026-05-12 and republished it on 2026-05-14 with Siemens ProductCERT material. The vulnerability text describes a Linux kernel XFS extended-attribute handling flaw: ENODATA/ENOATTR from disk can be mistaken for “attribute not found,” and in one code path can leave a null buffer pointer that may later be passed to xfs_trans_brelse(), creating a null-dereference risk. The sou [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39828

CVE-2025-39828 describes a Linux kernel ATM subsystem flaw in atmtcp_recv_control() where sendmsg()-originated messages were not adequately validated before reaching control handling. The advisory states this could let a local attacker abuse atmtcp_control handling to overwrite kernel pointers, which is why the issue was fixed by adding a pre_send() validation step. In the Siemens/CISA advisory set, the i [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39827

CVE-2025-39827 describes a reference-counting bug in the Linux kernel’s rose networking code that could let a rose_neigh object be freed while still referenced, resulting in a slab-use-after-free. The supplied CISA/Siemens advisory maps the issue to Siemens SIMATIC CN 4100 versions before 5.0 and credits Syzbot for reporting the problem.

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39826

CVE-2025-39826 is a medium-severity Linux kernel race condition affecting the rose networking code. The issue centers on a non-atomic reference counter in struct rose_neigh that could reach zero while other code paths, including a timer-driven path, still hold a reference. That creates a potential use-after-free condition and an availability impact. The published advisory context is an industrial-control/ [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39825

CVE-2025-39825 is a race-condition issue described in the Linux kernel SMB client rename(2) path. The source advisory says the rename flow can widen the window for concurrent opens on the target file while handling deferred closes, outstanding I/O, and deleted open handles. The cited fix is to unhash the dentry earlier so concurrent opens are blocked before the rename completes. The source rates the issue [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39824

CVE-2025-39824 appears in a CISA CSAF advisory published on 2026-05-12 and republished on 2026-05-14. The advisory maps the issue to Siemens SIMATIC CN 4100 versions before 5.0 and recommends updating to V5.0 or later. However, the embedded vulnerability text describes a Linux kernel HID use-after-free condition triggered by a crafted HID descriptor, so the product-to-vulnerability mapping in this source [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39823

CVE-2025-39823 is a HIGH-severity issue whose source description says the Linux kernel KVM x86 code path used guest-controlled indices in a way that needed speculative-execution hardening. The fix applies array_index_nospec() after bounds checks so guest-provided values are clamped before they can influence speculation. The advisory metadata associates the CVE with Siemens SIMATIC CN 4100 versions before [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39819

CVE-2025-39819 is a medium-severity Linux kernel SMB/CIFS issue described in Siemens and CISA advisory material. The reported bug is an inconsistent reference-count cleanup path in smb2_compound_op: when allocation of vars fails and -ENOMEM is returned, the cfile reference may not be dropped as expected, which can lead to resource leakage. The supplied advisory text says the fix adds an extra out cleanup [truncated]

HIGH Siemens CVE published 2026-05-12

CVE-2025-39817

CVE-2025-39817 is a Linux kernel efivarfs memory-safety issue that can cause a slab-out-of-bounds read in efivarfs_d_compare. The supplied advisory says the bug was observed on kernel 6.6 and present on master, and that parallel lookups involving an invalid filename can lead to a negative guid value and an out-of-bounds memcmp. The fix is to validate guid before the comparison. CISA published the advisory [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39813

CVE-2025-39813 covers a Linux kernel ftrace race condition that can trigger a WARN_ON_ONCE() in trace_printk_seq() during ftrace_dump when trace_pipe is being read at the same time. According to the supplied advisory metadata, the issue is associated with Siemens SIMATIC CN 4100 versions before 5.0 and was published by CISA on 2026-05-12, with a CISA republication of the Siemens ProductCERT advisory on 20 [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39812

CVE-2025-39812 is documented in a CISA-republished Siemens advisory as an uninitialized-field issue in Linux kernel SCTP IPv6 handling. The reported bug leaves sin6_scope_id and sin6_flowinfo insufficiently initialized in sctp_v6_from_sk(), which can trigger undefined behavior and KMSAN uninit-value reports during SCTP address comparison and listen-path processing. The source corpus ties the advisory to S [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39808

CVE-2025-39808 describes a Linux kernel HID issue in ntrig_report_version() where a missing null check can let hid_to_usb_dev() operate on an invalid USB parent path and trigger a page fault. The advisory source maps this to Siemens SIMATIC CN 4100 v<5.0 and recommends updating to V5.0 or later. Published by CISA on 2026-05-12 and republished on 2026-05-14, it is best treated as a medium-priority availability fix.

HIGH Siemens CVE published 2026-05-12

CVE-2025-39806

CVE-2025-39806 describes a slab out-of-bounds read in the Linux kernel HID multitouch path. A malicious HID device can provide a report descriptor smaller than 608 bytes, and mt_report_fixup() may still read byte offset 607 while checking whether it should patch the descriptor. The fix is to verify the descriptor is at least 608 bytes before any access at that offset. The source advisory rates the issue H [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39801

CVE-2025-39801 concerns a Linux kernel DWC3 endpoint-command timeout path where WARN_ON handling could trigger an avoidable kernel panic when panic_on_warn is enabled, or generate unnecessary call traces otherwise. The advisory links the issue to Siemens SIMATIC CN 4100 versions before 5.0 and says the problem was observed during fast software-controlled USB connect/disconnect test cases. From a defensive [truncated]

MEDIUM Siemens CVE published 2026-05-12

CVE-2025-39800

CVE-2025-39800 is a Linux kernel btrfs issue where an unexpected extent buffer generation at btrfs_copy_root() was previously only warned about, rather than causing the transaction to abort. According to the advisory text, that behavior could allow metadata with an unexpected generation to persist. CISA’s advisory for Siemens SIMATIC CN 4100 lists a vendor fix of V5.0 or later. The advisory was first publ [truncated]