PT-2025-30384 · Linux +11 · Linux Kernel +11
Published
2025-07-22
·
Updated
2025-12-16
·
CVE-2025-38352
CVSS v3.1
7.4
7.4
High
| Base vector | Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.1.147-1
Linux kernel versions prior to 6.6.101
Description
The Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the
posix-cpu-timers subsystem. This flaw is present in the handle posix cpu timers() and posix cpu timer del() functions. The vulnerability occurs when these functions run concurrently on an exiting task, potentially leading to a use-after-free scenario. Exploitation of this vulnerability could allow a local attacker to escalate privileges or cause a system crash. This vulnerability is actively exploited.Recommendations
Upgrade the Linux kernel to version 6.1.147-1 or later.
Upgrade the Linux kernel to version 6.6.101 or later.
Exploit
Fix
Race Condition
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Related Identifiers
ALSA-2025:15471
ALSA-2025:15472
ALSA-2025:15661
ALSA-2025:15662
ALT-PU-2025-12647
ASB-A-425282960
BDU:2025-10870
CESA-2025_15471
CESA-2025_15472
CESA-2025_15921
CVE-2025-38352
DLA-4327-1
DLA-4328-1
DSA-5973-1
ECHO-11F2-D185-A1F8
INFSA-2025_15471
INFSA-2025_15472
INFSA-2025_15661
LSN-0116-1
MGASA-2025-0218
MGASA-2025-0219
OESA-2025-2002
OESA-2025-2003
OESA-2025-2004
OESA-2025-2005
OESA-2025-2006
OESA-2025-2553
RHSA-2025:15662
RHSA-2025_15471
RHSA-2025_15472
RHSA-2025_15661
SUSE-SU-2025:02853-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:03023-1
SUSE-SU-2025:03283-1
SUSE-SU-2025:03314-1
SUSE-SU-2025:4315-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2025_03023-1
SUSE-SU-2025_03204-1
SUSE-SU-2025_03310-1
SUSE-SU-2025_03314-1
SUSE-SU-2025_03344-1
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7789-1
USN-7789-2
USN-7853-1
USN-7853-2
USN-7853-3
USN-7854-1
USN-7861-1
USN-7861-2
USN-7861-3
USN-7861-4
USN-7863-1
USN-7864-1
USN-7865-1
USN-7874-1
USN-7874-2
USN-7875-1
USN-7935-1
USN-7939-1
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
References · 5744
- 🔥 https://github.com/aels/CVE-2022-2586-LPE⭐ 18 🔗 3 · Exploit
- 🔥 https://github.com/sniper404ghostxploit/CVE-2022-2586⭐ 3 🔗 3 · Exploit
- https://ubuntu.com/security/CVE-2025-38287 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50140 · Security Note
- https://ubuntu.com/security/CVE-2024-56767 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-06105 · Security Note
- https://bdu.fstec.ru/vul/2025-06397 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2022-50405 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42064 · Security Note
- https://bdu.fstec.ru/vul/2025-15795 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-39714 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50151 · Security Note
- https://bdu.fstec.ru/vul/2025-10746 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-38164 · Security Note
- https://bdu.fstec.ru/vul/2025-04525 · Security Note