CVE-2025-38352: Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handleposixcputimers() and posixcputimerdel()
If an exiting non-autoreaping task has already passed exitnotify() and calls handleposixcputimers() from IRQ, it can be reaped by its parent or debugger right after unlocktasksighand().
If a concurrent posixcputimerdel() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cputimertaskrcu() and/or locktasksighand() will fail.
Add the tsk->exitstate check into runposixcputimers() to fix this.
This fix is not needed if CONFIGPOSIXCPUTIMERSTASKWORK=y, because exittaskwork() is called before exitnotify(). But the check still makes sense, taskworkadd(&tsk->posixcputimerswork.work) will fail anyway in this case.
Other sources
Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38352?
The severity of CVE-2025-38352 is categorized as medium due to its potential impact on system stability.
How do I fix CVE-2025-38352?
To fix CVE-2025-38352, update the Linux kernel to the latest stable version that includes the patch for this vulnerability.
What systems are affected by CVE-2025-38352?
CVE-2025-38352 affects various versions of the Linux kernel used in different distributions.
What are the potential consequences of CVE-2025-38352?
The potential consequences of CVE-2025-38352 include system instability and unexpected behavior during timer operations.
Is there an exploit available for CVE-2025-38352?
As of now, there is no known public exploit for CVE-2025-38352, but it is recommended to apply patches to mitigate risks.