A critical use-after-free vulnerability, tracked as CVE-2025-38352, has been identified in the Linux kernel's POSIX CPU timer implementation. The flaw arises from a race condition in the handle_posix_cpu_timers() function, which can be exploited when a process enters a zombie state and timer structures are prematurely freed while still in use. This vulnerability is particularly impactful on systems with CONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, notably affecting 32-bit Android kernels and Linux LTS 6.12.33.
A proof-of-concept (PoC) exploit for CVE-2025-38352 has been publicly released, demonstrating how attackers can leverage the race condition to trigger kernel memory corruption and potentially escalate privileges locally. The exploit involves creating a POSIX CPU timer, forcing a thread into a zombie state, and deleting the timer at a critical moment to induce a use-after-free scenario. Successful exploitation is evidenced by KASAN memory sanitizer warnings, and the vulnerability poses a significant risk for local privilege escalation on affected Linux systems.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A public proof-of-concept exploit was released for CVE-2025-38352, demonstrating exploitation of the Linux kernel POSIX timer vulnerability. The disclosure increased the risk of broader abuse and prompted urgent patching recommendations.
Reports indicated that CVE-2025-38352 was being actively exploited in targeted attacks. The flaw particularly raised concern for 32-bit Android devices and systems with CONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled.
Kernel patches were released to address CVE-2025-38352, a race condition use-after-free flaw in the Linux kernel's POSIX CPU timer implementation. The vulnerability can lead to kernel memory corruption and possible privilege escalation on affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcestreypaws.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.