{"id":"ASB-A-425282960","details":"In run_posix_cpu_timers of posix-cpu-timers.c, there is a possible way to trigger a use-after-free on a sigqueue object due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-425282960","CVE-2025-38352"],"modified":"2026-05-15T15:01:37.959123Z","published":"2025-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2025-09-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2025-09-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"severity":"High","vanir_signatures":[{"signature_type":"Line","id":"ASB-A-425282960-0d6867e2","target":{"file":"kernel/time/posix-cpu-timers.c"},"source":"https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb","digest":{"threshold":0.9,"line_hashes":["239550998081870972127451971872312053997","147150368589273284825147366725515272174","82833152002525841078026884179897054603"]},"deprecated":false,"signature_version":"v1"},{"signature_type":"Line","id":"ASB-A-425282960-553e0dda","target":{"file":"kernel/time/posix-cpu-timers.c"},"source":"https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83","digest":{"threshold":0.9,"line_hashes":["239550998081870972127451971872312053997","147150368589273284825147366725515272174","82833152002525841078026884179897054603"]},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","id":"ASB-A-425282960-d6dfad21","target":{"file":"kernel/time/posix-cpu-timers.c","function":"run_posix_cpu_timers"},"source":"https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83","digest":{"function_hash":"328631927418429210242873994005901180136","length":154},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","id":"ASB-A-425282960-e83512d2","target":{"file":"kernel/time/posix-cpu-timers.c","function":"run_posix_cpu_timers"},"source":"https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb","digest":{"function_hash":"328631927418429210242873994005901180136","length":154},"deprecated":false,"signature_version":"v1"}],"types":["EoP"],"fixes":["https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb","https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83"],"spl":"2025-09-05"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-425282960.json"}}],"schema_version":"1.7.5"}