CVE-2025-38352 is an actively exploited Linux kernel race condition in POSIX CPU timer processing. A timing flaw between handle_posix_cpu_timers() and posix_cpu_timer_del() while a task exits can cause a use-after-free, allowing a local low-privileged attacker to crash the host or escalate privileges. Red Hat rates the issue Important with a CVSS v3.1 score of 7.8; no qualifying mitigation is available.
Red Hat released fixes across affected kernel packages, including kernel-rt-4.18.0-553.74.1.rt7.415.el8_10 for Red Hat Enterprise Linux 8 Real Time, Real Time for NFV, and x86_64 Extended Life Cycle 8.10 deployments. Organizations should install the applicable updated kernel packages and reboot affected systems promptly, prioritizing hosts where untrusted or low-privileged local access is possible.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:15662 for the RHEL 10 kernel and RHSA-2025:15660 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernels, addressing CVE-2025-38352.
Red Hat released fixes for CVE-2025-38352 through RHSA-2025:15646 for RHEL 7 Extended Lifecycle Support kernel-rt, RHSA-2025:15648 for the RHEL 7 ELS kernel, RHSA-2025:15656 for RHEL 8.2 Advanced Update Support, and RHSA-2025:15647 for RHEL 8.6 Advanced Mission Critical Update Support.
Red Hat released RHSA-2025:15921, fixing CVE-2025-38352 in the RHEL 8 kpatch-patch package.
Red Hat released RHSA-2025:15471 for the RHEL 8 kernel and RHSA-2025:15472 for the RHEL 8 kernel-rt packages, fixing the POSIX CPU timer race condition tracked as CVE-2025-38352. The kernel-rt advisory affected Real Time, Real Time for NFV, and x86_64 Extended Life Cycle 8.10 deployments.
The Linux kernel CVE team assigned CVE-2025-38352 to a POSIX CPU timer race between handle_posix_cpu_timers() and posix_cpu_timer_del(). The upstream fix adds an exit_state check in run_posix_cpu_timers() and was included in stable kernels from 5.4.295 through 6.16-rc2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.