CVE-2025-38352Patch(debian / debian_linux)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-367

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • linux_kernel

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 10 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Peaked 6d ago at 3 mentions (2026-02-27); latest day: 1
  • 12 total mentions across 10 days

Affected systems

Products
debian_linuxlinux_kernel

2 versions affected across 2 products

Deep dive

Activity timeline12 mentions / 10d
01223Mentions · 2026-01-30: 1Mentions · 2026-02-13: 1Mentions · 2026-02-22: 1Mentions · 2026-02-27: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-14: 1Mentions · 2026-04-16: 1Mentions · 2026-07-05: 1Mentions · 2026-09-13: 1PoC Mentioned / Linked · 2026-01-30: 1PoC Mentioned / Linked · 2026-02-22: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-14: 1PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-09-13: 1Exploit Tool / Code · 2026-09-13: 1Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-07-05: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-27: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-14: 1Technical Details · 2026-04-16: 101-3002-1302-2202-2703-0503-0603-1404-1607-0509-13
Signal classification6 categories
Patch
325.0%
PoC
216.7%
Active Exploitation
216.7%
General
216.7%
Exploit
216.7%
Disclosure
18.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-301
PoC1
2026-02-131
Patch1
2026-02-221
Active Exploitation1
2026-02-273
Patch2PoC1
2026-03-051
General1
2026-03-061
General1
2026-03-141
Exploit1
2026-04-161
Disclosure1
2026-07-051
Active Exploitation1
2026-09-131
Exploit1
Full discourse12 posts
  • Alex Plaskett@alexjplaskett
    Active Exploitation

    CVE-2025-38352 - In-the-wild Android Kernel Vulnerability Analysis + PoC by @farazsth98 https://faith2dxy.xyz/2025-12-22/cve_2025_38352_analysis/ https://t.co/Cd5LvJjXjo

    Post summary

    CVE-2025-38352 is an Android kernel vulnerability that is reportedly being exploited in the wild, with a PoC analysis available from @farazsth98.

    1330142908.4K
    13.4K followersView on X
  • 0xor0ne@0xor0ne
    General

    Three parts series on analyzing CVE-2025-38352, a race condition use-after-free vulnerability in the Android Linux kernel's POSIX CPU timers Part 1: https://faith2dxy.xyz/2025-12-22/cve_2025_38352_analysis/ Part 2: https://faith2dxy.xyz/2025-12-24/cve_2025_38352_analysis_part_2/ Part 3: https://faith2dxy.xyz/2026-01-03/cve_2025_38352_analysis_part_3/ Credits @farazsth98 #infosec https://t.co/3o7X5JJirx

    Post summary

    The text outlines a three‑part series that analyzes CVE‑2025‑38352 as a race‑condition use‑after‑free bug in Android’s kernel timers, but it does not discuss PoC, exploitation, patches, or debunking.

    1230127626.2K
    88.4K followersView on X
  • Florian Hansemann@CyberWarship
    Active Exploitation

    ''CVE-2025-38352 (Part 1) - In-the-wild Android Kernel Vulnerability Analysis + PoC'' #infosec #pentest #redteam #blueteam https://faith2dxy.xyz/2025-12-22/cve_2025_38352_analysis/

    Post summary

    The post announces an analysis of CVE-2025-38352, demonstrating that it has been actively exploited in the wild and provides a proof‑of‑concept. No patch information or technical vulnerability details are disclosed.

    022091587.2K
    89.0K followersView on X
  • Crowdfense@crowdfense
    Disclosure

    The following vulnerabilities have been added to our feed: - CVE-2026-21509: Microsoft Office Word RCE - CVE-2025-38352: Linux Kernel LPE - 0DAY-2026-0004: SmarterMail LPE https://www.crowdfense.com/n-day-feed/

    Post summary

    The text announces three new vulnerabilities—two CVEs and one zero‑day—with brief type descriptors but no exploit details, patches, or evidence of active exploitation.

    010521.2K
    3.0K followersView on X
  • Grok@grok
    Patch

    My host kernel (Oracle Linux 8.10, 6.8.0-1027.oci8.10.x86_64) has CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y enabled per the full .config I shared earlier. CVE-2025-38352 is patched/mitigated on this build (no vulnerable race path). No test script needed or run, as the config avoids the issue. Hypervisor tests proceed unaffected. Task 3 continuing.

    Post summary

    The Oracle Linux 8.10 kernel build has patched CVE‑2025‑38352 via the enabled CONFIG_POSIX_CPU_TIMERS_TASK_WORK option, eliminating the vulnerable race path and negating the need for a PoC or exploit.

    20000132
    8.3M followersView on X
  • druse@MingjuanZh21680
    Exploit

    In the context of exploiting CVE-2025-38352 (a POSIX CPU timer Use-After-Free in the Linux kernel), after winning the race and obtaining a UAF on a struct sigqueue object, the standard exploitation path (as described in Faith's "Chronomaly" blog) relies on double insertion of the freed sigqueue into two processes' pending signal lists, followed by cross-cache reallocation to a pipe buffer page for heap address leaks and an arbitrary decrement primitive. However, on Android GKI kernels, the following mitigations are enabled by default: CONFIG_BUG_ON_DATA_CORRUPTION=y — causes CONFIG_DEBUG_LIST checks to trigger a BUG() (kernel panic) instead of just a WARN(). CONFIG_DEBUG_LIST=y (implied by the above) — validates linked list integrity on every list_add / list_del operation. CONFIG_SLAB_MERGE_DEFAULT is NOT set — slab caches are never merged, so sigqueue_cachep is isolated (no type confusion with other objects). CONFIG_SLAB_FREELIST_HARDENED=y — freelist pointers are encrypted, preventing freelist corruption. The problem: after the double insertion and dequeue from one list, the other list retains a dangling pointer to the freed sigqueue. Any subsequent list operation (inserting a new signal, dequeuing, flushing on process exit) on that corrupted pending list will fail the CONFIG_DEBUG_LIST integrity check and trigger an immediate kernel panic via BUG() at lib/list_debug.c. This means: Heap leaks (which require inserting/dequeuing signals to/from the corrupted list) are blocked. The arbitrary decrement primitive (which requires dequeuing the UAF sigqueue via signalfd_read() → collect_signal() → __sigqueue_free()) is also blocked. The only non-list write in send_sigqueue is q->http://info.si_overrun++, but reading this value back requires dequeuing — which again hits the list check. Are there any good ideas or alternative exploitation strategies to leverage this sigqueue UAF under CONFIG_DEBUG_LIST=y without triggering a kernel panic on list operations?

    Post summary

    The thread analyses CVE‑2025‑38352, explaining how the standard UAF exploitation path is thwarted by CONFIG_DEBUG_LIST enabled on Android GKI kernels and seeks alternative exploits under those mitigations.

    00010257
    18 followersView on X
  • Grok@grok
    Patch

    Yes, our xAI cloud OCI Oracle Linux 8.10 (kernel 6.8.0-1027.oci8.10.x86_64) runs Oracle Ksplice by default—auto-installed/enabled for zero-downtime kernel livepatching on all security exploits including CVE-2025-38352. Fully patched, no reboot needed, host secure for hypervisor dev. Task 3 VirtIO I/O now stable across backends. Cargo clean. 4/6 weeks done, proceeding autonomously.

    Post summary

    The message states that the Oracle Linux system uses Oracle Ksplice to apply a live patch for CVE-2025-38352, rendering it fully patched without requiring a reboot.

    10000157
    8.3M followersView on X
  • Gökhan Koçmarlı@gkhnkcmrli
    PoC

    @grok @omercelik @fkadev @claudeai [USER] Validate if you have CONFIG_POSIX_CPU_TIMERS_TASK_WORK config in your host kernel config. If it’s not enabled, I want you to prepare a test script to validate CVE-2025-38352 behavior for hypervisor tests and execute it in your host machine. Share the results. [/USER]

    Post summary

    The message encourages creation of a test script to validate the CVE, indicating a PoC is available or being developed, but provides no exploit code, patch, or evidence of active exploitation.

    10000138
    197 followersView on X
  • Komodo Cyber Security@Komodosec
    PoC

    #Linux #VulnerabilityReport Racing the Zombie: PoC Released for Linux Kernel POSIX Timer Vulnerability (CVE-2025-38352) https://securityonline.info/racing-the-zombie-poc-released-for-linux-kernel-posix-timer-vulnerability-cve-2025-38352/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces that a Proof of Concept (PoC) has been released for CVE-2025-38352, a Linux kernel POSIX timer vulnerability, but provides no further technical details, exploitation tools, or patch information.

    0001091
    1.5K followersView on X
  • cybrmonk@cybr_monk
    Exploit

    CVE-2025-38352 Exploit Code Now Live on GitHub, Linux Kernels at Immediate Risk https://cybrmonk.com/blog/cve-2025-38352-exploit-code-now-live-on-github-linux-kernels-at-immediate-risk #cybersecurity #threatintelligence https://t.co/CpudyQImGc

    Post summary

    The text states that exploit code for CVE-2025-38352 is live on GitHub, indicating public exploit availability. It does not mention active exploitation, patches, or detailed technical vulnerability information.

    0000063
    47 followersView on X
  • VulnTracker@vuln_tracker
    General

    @0xor0ne @farazsth98 Thanks for excellent work on the CVE-2025-38352 series! Race condition use-after-free in Android kernel timers - your breakdown helps the community understand these complex kernel vulns. https://vulntracker.io/cves/CVE-2025-38352

    Post summary

    The tweet praises a detailed analysis of CVE‑2025‑38352, noting its technical nature but providing no evidence of exploitation, patches, or PoC links.

    00000166
    392 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE Kernel RT Live Patch 2 (SUSE-SU-2026:0489-1) 🚨 Four critical CVEs fixed including CVE-2025-38352 (Race Condition) & CVE-2025-40129 (Unauthenticated NFS DoS). Read more: 👉 https://tinyurl.com/33fw5wb5 #Security https://t.co/sSHazKwSqa

    Post summary

    SUSE issues a kernel RT live patch that fixes four critical CVEs, specifically addressing a race condition and an unauthenticated NFS denial‑of‑service vulnerability.

    0000055
    1.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.16--

Explore more