Database/Kernel, userspace & hypervisor
Linux kernel (posix-cpu-timers): TOCTOU race between handle_posix_cpu_timers() and posix_cpu_timer_del()
CVSS 7.8CVE-2025-38352Kernel, userspace & hypervisorKnown exploitedcurated
Impact
TOCTOU race between handle_posix_cpu_timers() and posix_cpu_timer_del() - local privilege escalation, exploited in the wild [KEV]
Who can reach it
Any tenant process in a container
What to do
Livepatchable; otherwise drain + reboot. No capabilities or namespaces needed, so container hardening does not mitigate it
References
Related entries
- Linux i915 GPU kernel driver (GT timeline / VMA allocation): A timeline is left held when VMA allocation fails, soCVE-2025-38389 · Linux i915 GPU kernel driver (GT timeline / VMA allocation)High
- Linux kernel SMC (struct smc_sock type confusion with inet_sock): Struct smc_sock does not embed struct inet_sock asCVE-2025-38475 · Linux kernel SMC (struct smc_sock type confusion with inet_sock)High
- Linux kernel (net/xfrm): The guard that forbids changing a collect_md xfrm interface never fired, so a changelink putsCVE-2025-38500 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedCVE-2025-38594 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (net/tls): KTLS assumes it owns the TCP receive queue. When another reader drains bytes first, the oldCVE-2025-38616 · Linux kernel (net/tls)High
- Linux kernel (net/xfrm): If the task is preempted onto another CPU during SA lookup, a hit in the per-CPU state cacheCVE-2025-38675 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.