# CVE-2025-38352

## Summary

- **CVE ID:** CVE-2025-38352
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jul 22, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

If an exiting non-autoreaping task has already passed exit_notify() and
calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent
or debugger right after unlock_task_sighand().

If a concurrent posix_cpu_timer_del() runs at that moment, it won't be
able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or
lock_task_sighand() will fail.

Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.

This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because
exit_task_work() is called before exit_notify(). But the check still
makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail
anyway in this case.

## Affected Products

- Linux — Linux (0bdd2ed4138ec04e09b4f8165981efc99e439f55)
- Linux — Linux (2.6.36)
- Linux — Linux (0)
- Linux — Linux (5.4.295)
- Linux — Linux (5.10.239)
- Linux — Linux (5.15.186)
- Linux — Linux (6.1.142)
- Linux — Linux (6.6.94)
- Linux — Linux (6.12.34)
- Linux — Linux (6.15.3)
- Linux — Linux (6.16)

## References

- [CNA](https://git.kernel.org/stable/c/78a4b8e3795b31dae58762bc091bb0f4f74a2200)
- [CNA](https://git.kernel.org/stable/c/c076635b3a42771ace7d276de8dc3bc76ee2ba1b)
- [CNA](https://git.kernel.org/stable/c/2f3daa04a9328220de46f0d5c919a6c0073a9f0b)
- [CNA](https://git.kernel.org/stable/c/764a7a5dfda23f69919441f2eac2a83e7db6e5bb)
- [CNA](https://git.kernel.org/stable/c/2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff)
- [CNA](https://git.kernel.org/stable/c/c29d5318708e67ac13c1b6fc1007d179fb65b4d7)
- [CNA](https://git.kernel.org/stable/c/460188bc042a3f40f72d34b9f7fc6ee66b0b757b)
- [CNA](https://git.kernel.org/stable/c/f90fff1e152dedf52b932240ebbd670d83330eca)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-38352)
- [CISA-ADP](https://github.com/farazsth98/chronomaly)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.25%
- **EPSS Percentile:** 68.0

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Sep 4, 2025
- **Due Date:** Sep 25, 2025

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._