Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38352

65
FAUCET Score

CVE-2025-38352 is a high-severity race condition vulnerability in the Linux kernel's posix-cpu-timers component, affecting Debian and other Linux distributions. This flaw allows a non-autoreaping task to be reaped prematurely, leading to a race condition with posix_cpu_timer_del() that can prevent proper timer detection. With a CVSS score of 7.4, the vulnerability has a high impact on confidentiality, integrity, and availability, and is difficult to exploit locally. Notably, this CVE is actively exploited in the wild, specifically targeting vulnerable Linux kernels v5.10.x, and has garnered significant community discussion and media coverage, including an Android kernel exploit named "Chronomaly" available on GitHub.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.36, < 5.4.295CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.239CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.186CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.142CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.94CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.34%
Probability of exploitation in next 30 days
EPSS Percentile
68.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Sep 4, 2025
This CVE's current EPSS score of 0.0135 is in the 95th percentile among its peer group of 157 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (38)

linuxpatch availablevia osv
Product: KernelFixed in: 5.4.295
linuxpatch availablevia osv
Product: KernelFixed in: 5.10.239
linuxpatch availablevia osv
Product: KernelFixed in: 5.15.186
linuxpatch availablevia osv
Product: KernelFixed in: 6.1.142
linuxpatch availablevia osv
Product: KernelFixed in: 6.6.94
linuxpatch availablevia osv
Product: KernelFixed in: 6.12.34
linuxpatch availablevia osv
Product: KernelFixed in: 6.15.3
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-2 on Azure Linux 3.0Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 17085-17084Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 19880-17084Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.1-1 on Azure Linux 3.0Fixed in: 6.6.96.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: kernel-0:3.10.0-1160.139.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.74.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: kernel-0:4.18.0-193.168.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-305.172.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: kernel-0:4.18.0-305.172.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-372.160.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-372.160.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-372.160.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-477.110.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-570.42.2.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-0:5.14.0-70.146.1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-rt-0:5.14.0-70.146.1.rt21.218.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: kernel-0:5.14.0-284.137.1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: kernel-rt-0:5.14.0-284.137.1.rt14.422.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.88.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: kernel-rt-0:3.10.0-1160.139.1.rt56.1291.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.74.1.rt7.415.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel-0:6.12.0-55.32.1.el10_0
View patch
googlevendor investigatingvia android_bulletin
View patch
grafanavendor investigatingvia llm_extracted
View patch

Vendor Advisories (5)

grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
linuxCVE-2025-38352HIGH

posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

Jul 22, 2025
redhatCVE-2025-38352Important

kernel: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

Jul 22, 2025
microsoft2025-Jul/CVE-2025-38352Moderate

posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

Jul 8, 2025
googlegoogle:android-2025-09-01CRITICAL

September

References

github.com / farazsth98/chronomaly
Exploit
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
git.kernel.org / stable/c/2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff
Patch
git.kernel.org / stable/c/2f3daa04a9328220de46f0d5c919a6c0073a9f0b
Patch
git.kernel.org / stable/c/460188bc042a3f40f72d34b9f7fc6ee66b0b757b
Patch
git.kernel.org / stable/c/764a7a5dfda23f69919441f2eac2a83e7db6e5bb
Patch
git.kernel.org / stable/c/78a4b8e3795b31dae58762bc091bb0f4f74a2200
Patch
git.kernel.org / stable/c/c076635b3a42771ace7d276de8dc3bc76ee2ba1b
Patch
git.kernel.org / stable/c/c29d5318708e67ac13c1b6fc1007d179fb65b4d7
Patch
git.kernel.org / stable/c/f90fff1e152dedf52b932240ebbd670d83330eca
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory