CVE-2025-38352
Description
In the Linux kernel, the following vulnerability has been resolved:posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()If an exiting non-autoreaping task has already passed exit_notify() andcalls handle_posix_cpu_timers() from IRQ, it can be reaped by its parentor debugger right after unlock_task_sighand().If a concurrent posix_cpu_timer_del() runs at that moment, it wont beable to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/orlock_task_sighand() will fail.Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, becauseexit_task_work() is called before exit_notify(). But the check stillmakes sense, task_work_add(&tsk->posix_cputimers_work.work) will failanyway in this case.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 11.1 | Windows |
| linux security update(DSA-5973-1) DSA-5973-1 linux-cpupower_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-doc_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-doc-6.1_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-686-dbg_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-686-pae-dbg_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-cpupower_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-amd64-signed-template_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-cloud-amd64-dbg_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-i386-signed-template_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-rt-686-pae-dbg_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-rt-amd64-dbg_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-amd64-dbg_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-config-6.1_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-config-6.1_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-compiler-gcc-12-x86_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-kbuild-6.1_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower1_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower1_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower-dev_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower-dev_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 hyperv-daemons_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 hyperv-daemons_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 bpftool_7.1.0+6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-compiler-gcc-12-x86_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 usbip_2.0+6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 usbip_2.0+6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 rtla_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 rtla_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-source-6.1_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-source_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-libc-dev_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 bpftool_7.1.0+6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-libc-dev_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-perf_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-kbuild-6.1_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-perf_6.1.147-1_i386.deb | Linux |
| Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2025-38352) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234