Executive brief
A race condition vulnerability exists in the Linux kernel's timing mechanisms. This flaw could allow a local attacker to compromise the confidentiality, integrity, and availability of the system. The vulnerability has been observed being exploited in the wild, making immediate patching a priority for maintaining system security and operational stability.
Technical details
A race condition exists between handle_posix_cpu_timers() and posix_cpu_timer_del() in the Linux kernel. When an exiting non-autoreaping task passes exit_notify() and triggers handle_posix_cpu_timers() from an interrupt context, it may be reaped by a parent or debugger immediately after releasing the task signal handler lock. A concurrent deletion request may then fail to detect that the timer is still firing because RCU or lock lookups fail. This TOCTOU flaw allows for potential memory corruption or privilege escalation. The issue is mitigated if CONFIG_POSIX_CPU_TIMERS_TASK_WORK is enabled, but a fix has been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel 2.6.36 to 5.4.295, 5.5 to 5.10.239, 5.11 to 5.15.186, 5.16 to 6.1.142, 6.2 to 6.6.94, 6.7 to 6.12.34, 6.13 to 6.15.3
Timeline
- 2025-09-04: disclosed: Vulnerability published and added to CISA KEV catalog
- 2025-09-04: kev added
- 2025-09-04: exploited