CVE-2025-38352

Aliases:RHSA-2025:15662UBUNTU-CVE-2025-38352DEBIAN-CVE-2025-38352
Advisory lineage Upstream: 0 Downstream: 136
Analyzed
Published: 22 Jul 2025, 08:04
Last modified:08 Sept 2026, 15:32

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
1.25% LOW
1% probability +1.21%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Jul 2025, 08:04
Published
Vulnerability first disclosed
04 Sept 2025, 00:00
Added to CISA KEV
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
25 Sept 2025, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
08 Sept 2026, 15:32
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 1.25% Percentile: 68%

Techniques & Countermeasures

  • CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition

    The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Affected Systems

  • debianlinux

    < 5.10.244-1 | < 6.1.147-1 | < 6.12.35-1 | < 6.12.35-1

  • debianlinux-6.1

    < 6.1.153-1~deb11u1

  • ubuntulinux

    < 3.13.0-210.261 | < 4.4.0-274.308 | < 4.15.0-243.255 | < 5.4.0-223.243 | < 5.15.0-156.166 | < 6.8.0-87.88

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    < 4.4.0-1149.155 | < 4.4.0-1187.202 | < 4.15.0-1186.199 | < 5.4.0-1152.162 | < 5.15.0-1092.99 | < 6.8.0-1042.44

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1092.99~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1152.162~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    < 6.14.0-1013.13~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1042.44~22.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2124.130 | all | < 5.4.0-1152.162+fips1 | < 5.15.0-1092.99+fips1 | < 6.8.0-1042.44+fips1

  • ubuntulinux-aws-hwe

    < 4.15.0-1186.199~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1194.209~14.04.1 | < 4.15.0-1194.209~16.04.1 | all | < 5.4.0-1156.163 | < 5.15.0-1096.105 | < 6.8.0-1044.50

  • ubuntulinux-azure-4.15

    < 4.15.0-1194.209

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1096.105~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1156.163~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1044.50~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2104.110 | all | < 5.4.0-1157.164+fips1 | < 5.15.0-1096.105+fips1 | < 6.8.0-1044.50+fips1

  • ubuntulinux-azure-nvidia

    < 6.8.0-1029.32

  • ubuntulinux-azure-nvidia-6.14

    < 6.14.0-1007.7

  • ubuntulinux-bluefield

    all | < 5.4.0-1111.118 | < 5.15.0-1076.78 | < 6.8.0-1013.17

  • ubuntulinux-fips

    < 4.4.0-1119.126 | all | < 4.15.0-1141.153 | < 5.4.0-1126.136 | < 5.15.0-156.166+fips1 | < 6.8.0-87.88+fips1

  • ubuntulinux-gcp

    < 4.15.0-1179.196~16.04.1 | all | < 5.4.0-1155.164 | < 5.15.0-1092.101 | < 6.8.0-1043.46

  • ubuntulinux-gcp-4.15

    < 4.15.0-1179.196

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1092.101~20.04.1

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1155.164~18.04.1

Showing first 50 affected entries in server-rendered view.

References (61)