Answer in brief
CVE-2025-38352 records a High severity vulnerability in posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del(). The current sources mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38352 records a High severity vulnerability in posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del(). The current sources mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <78a4b8e3795b31dae58762bc091bb0f4f74a2200 || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <c076635b3a42771ace7d276de8dc3bc76ee2ba1b || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <2f3daa04a9328220de46f0d5c919a6c0073a9f0b || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <764a7a5dfda23f69919441f2eac2a83e7db6e5bb || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <c29d5318708e67ac13c1b6fc1007d179fb65b4d7 || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <460188bc042a3f40f72d34b9f7fc6ee66b0b757b || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <f90fff1e152dedf52b932240ebbd670d83330eca | 78a4b8e3795b31dae58762bc091bb0f4f74a2200, c076635b3a42771ace7d276de8dc3bc76ee2ba1b, 2f3daa04a9328220de46f0d5c919a6c0073a9f0b, 764a7a5dfda23f69919441f2eac2a83e7db6e5bb, 2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff, c29d5318708e67ac13c1b6fc1007d179fb65b4d7, 460188bc042a3f40f72d34b9f7fc6ee66b0b757b, f90fff1e152dedf52b932240ebbd670d83330eca |
| Linux/Linuxgeneric | 2.6.36 | Not reported |
Published upstream
Jul 22, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 4, 2025
Evidence: source:kev:kev:kev:recordIn the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <78a4b8e3795b31dae58762bc091bb0f4f74a2200 || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <c076635b3a42771ace7d276de8dc3bc76ee2ba1b || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <2f3daa04a9328220de46f0d5c919a6c0073a9f0b || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <764a7a5dfda23f69919441f2eac2a83e7db6e5bb || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <c29d5318708e67ac13c1b6fc1007d179fb65b4d7 || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <460188bc042a3f40f72d34b9f7fc6ee66b0b757b || >=0bdd2ed4138ec04e09b4f8165981efc99e439f55 <f90fff1e152dedf52b932240ebbd670d83330eca | 78a4b8e3795b31dae58762bc091bb0f4f74a2200, c076635b3a42771ace7d276de8dc3bc76ee2ba1b, 2f3daa04a9328220de46f0d5c919a6c0073a9f0b, 764a7a5dfda23f69919441f2eac2a83e7db6e5bb, 2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff, c29d5318708e67ac13c1b6fc1007d179fb65b4d7, 460188bc042a3f40f72d34b9f7fc6ee66b0b757b, f90fff1e152dedf52b932240ebbd670d83330eca |
| Linux/Linuxgeneric | 2.6.36 | Not reported |
Published upstream
Jul 22, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 4, 2025
Evidence: source:kev:kev:kev:recordIn the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case.
Quoted source text, attributed separately from HOL analysis.