posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
Published Jul 22, 2025 ·Due Sep 25, 2025
7.8
HIGHCVSS 3.1
EPSS 1.29%
Description
If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand().
If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail.
Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.
This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.36
Unaffected
- ≥ 0, < 2.6.36
- ≥ 5.10.239, ≤ 5.10.*
- ≥ 5.15.186, ≤ 5.15.*
- ≥ 5.4.295, ≤ 5.4.*
- ≥ 6.1.142, ≤ 6.1.*
- ≥ 6.12.34, ≤ 6.12.*
- ≥ 6.15.3, ≤ 6.15.*
- 6.16
- ≥ 6.6.94, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
Configuration 1
- ≥ 2.6.36 · < 5.4.295
- ≥ 5.5 · < 5.10.239
- ≥ 5.11 · < 5.15.186
- ≥ 5.16 · < 6.1.142
- ≥ 6.2 · < 6.6.94
- ≥ 6.7 · < 6.12.34
- ≥ 6.13 · < 6.15.3
- 6.16
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-55.32.1.el10_0
Fixed · RHSA-2025:15662
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-0:3.10.0-1160.139.1.el7
Fixed · RHSA-2025:15648
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-rt-0:3.10.0-1160.139.1.rt56.1291.el7
Fixed · RHSA-2025:15646
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.74.1.el8_10
Fixed · RHSA-2025:15471
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.74.1.rt7.415.el8_10
Fixed · RHSA-2025:15472
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2025:15921
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.168.1.el8_2
Fixed · RHSA-2025:15656
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.172.1.el8_4
Fixed · RHSA-2025:15660
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.172.1.el8_4
Fixed · RHSA-2025:15660
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.160.1.el8_6
Fixed · RHSA-2025:15647
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.160.1.el8_6
Fixed · RHSA-2025:15647
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.160.1.el8_6
Fixed · RHSA-2025:15647
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2025:16045
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.110.1.el8_8
Fixed · RHSA-2025:15649
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2025:16008
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.42.2.el9_6
Fixed · RHSA-2025:15661
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.42.2.el9_6
Fixed · RHSA-2025:15661
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2025:15798
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-0:5.14.0-70.146.1.el9_0
Fixed · RHSA-2025:15670
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-rt-0:5.14.0-70.146.1.rt21.218.el9_0
Fixed · RHSA-2025:15658
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2025:15933
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.137.1.el9_2
Fixed · RHSA-2025:15669
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.137.1.rt14.422.el9_2
Fixed · RHSA-2025:15657
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2025:15931
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.88.1.el9_4
Fixed · RHSA-2025:15668
Red Hat Enterprise Linux 9.4 Extended Update Support
kpatch-patch
Fixed · RHSA-2025:15932
Red Hat Enterprise Linux 6
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-55.32.1.el10_0 | Fixed | RHSA-2025:15662 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-0:3.10.0-1160.139.1.el7 | Fixed | RHSA-2025:15648 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-rt-0:3.10.0-1160.139.1.rt56.1291.el7 | Fixed | RHSA-2025:15646 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.74.1.el8_10 | Fixed | RHSA-2025:15471 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.74.1.rt7.415.el8_10 | Fixed | RHSA-2025:15472 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2025:15921 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.168.1.el8_2 | Fixed | RHSA-2025:15656 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.172.1.el8_4 | Fixed | RHSA-2025:15660 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.172.1.el8_4 | Fixed | RHSA-2025:15660 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.160.1.el8_6 | Fixed | RHSA-2025:15647 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.160.1.el8_6 | Fixed | RHSA-2025:15647 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.160.1.el8_6 | Fixed | RHSA-2025:15647 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2025:16045 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.110.1.el8_8 | Fixed | RHSA-2025:15649 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2025:16008 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.42.2.el9_6 | Fixed | RHSA-2025:15661 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.42.2.el9_6 | Fixed | RHSA-2025:15661 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2025:15798 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-0:5.14.0-70.146.1.el9_0 | Fixed | RHSA-2025:15670 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-rt-0:5.14.0-70.146.1.rt21.218.el9_0 | Fixed | RHSA-2025:15658 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2025:15933 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.137.1.el9_2 | Fixed | RHSA-2025:15669 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.137.1.rt14.422.el9_2 | Fixed | RHSA-2025:15657 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2025:15931 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.88.1.el9_4 | Fixed | RHSA-2025:15668 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kpatch-patch | Fixed | RHSA-2025:15932 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This CVE is rated with Important severity because it may allow an attacker with local user access to escalate their privileges on a target system.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (19)
- https://access.redhat.com/security/cve/CVE-2025-38352 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2382581 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22297 Advisory
- https://git.kernel.org/stable/c/2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff Patch
- https://git.kernel.org/stable/c/2f3daa04a9328220de46f0d5c919a6c0073a9f0b Patch
- https://git.kernel.org/stable/c/460188bc042a3f40f72d34b9f7fc6ee66b0b757b Patch
- https://git.kernel.org/stable/c/764a7a5dfda23f69919441f2eac2a83e7db6e5bb Patch
- https://git.kernel.org/stable/c/78a4b8e3795b31dae58762bc091bb0f4f74a2200 Patch
- https://git.kernel.org/stable/c/c076635b3a42771ace7d276de8dc3bc76ee2ba1b Patch
- https://git.kernel.org/stable/c/c29d5318708e67ac13c1b6fc1007d179fb65b4d7 Patch
- https://git.kernel.org/stable/c/f90fff1e152dedf52b932240ebbd670d83330eca Patch
- https://github.com/farazsth98/chronomaly exploit
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing ListThird Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025072229-CVE-2025-38352-f1de@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38352
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-38352 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2025-38352
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
ENISA EUVD
GitHub
No data