{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98258","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.332Z","datePublished":"2026-10-06T08:45:23.379Z","dateUpdated":"2026-10-07T06:49:46.515Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:46.515Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Prevent freeing a timer which is queued on the expiry list\n\nKijo analyzed another race in the POSIX CPU timer code:\n\nCommit bf635681c906 converted cpu_timer::firing from a tristate value to a\nboolean. This lost the distinction between \"not owned by the firing list\"\nand \"still owned, but delivery was canceled\". The resulting race is:\n\n    expiry handler              timer_settime()        timer_delete()\n    --------------              ---------------        --------------\n    collect timer onto\n    private firing list\n    firing = true\n                                observes firing = true\n                                firing = false\n                                return TIMER_RETRY\n                                wait for handler\n                                                       observes firing = false\n                                                       finish deletion\n                                                       unhash and free timer\n    resume list traversal\n    read freed elist.next\n    -> UAF\n\nThe firing bit is clearly the wrong indicator since that commit.\n\nCheck whether the timer is queued on the expiry list or not instead. If it\nis queued clear the firing bit to prevent signal delivery as before and\nreturn TIMER_RETRY so the caller unlocks the timer which allows the expiry\ncode to make progress and remove it from the list."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Triggered only through local syscalls timer_create() with a CPU-time clock, timer_settime() and timer_delete(), which reach posix_cpu_timer_set()/posix_cpu_timer_del() and race handle_posix_cpu_timers(); no remote peer supplies any input.\nAC:L - The attacker controls all three sides of the race: they make the timer expire by burning CPU, and run timer_settime() and timer_delete() on their own timer from sibling threads. Putting many timers on the firing list widens the traversal window, and the handler is preemptible task_work, so the attempt can be repeated at will.\nPR:L - posix CPU timers are available to any unprivileged process on its own threads or process; posix_cpu_timer_create(), timer_settime and timer_delete do no capability check, so an ordinary local user account is enough.\nUI:N - The attacker's own process creates, arms and deletes the timers; no other user or administrator has to do anything.\nS:U - The memory corruption is in the kernel's own k_itimer slab objects and leads to kernel privilege escalation in the same security authority, with no hypervisor or IOMMU boundary crossed.\nC:H - After kfree_rcu frees the k_itimer, the handler keeps using it through the cached it.cpu.elist next pointer. A sprayed replacement object makes the handler follow attacker-chosen list pointers and k_itimer fields, the same primitive class used in the in-the-wild CVE-2025-38352 exploit, so kernel memory disclosure is achievable.\nI:H - The handler does list_del_init() on the freed timer's elist and writes firing/handling, so it writes into reallocated memory. With a controlled replacement, the list unlink becomes a write primitive that can be built into privilege escalation.\nA:H - Even an unexploited race corrupts the slab or makes the handler dereference a freed or reused list pointer, producing a KASAN report, list corruption BUG or kernel oops that crashes the system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/time/posix-cpu-timers.c"],"versions":[{"version":"bf635681c906ad056d1fda325de8d1c12c9f8201","lessThan":"9971dac1a77845ff467146915fcbb9170f6a8209","status":"affected","versionType":"git"},{"version":"bf635681c906ad056d1fda325de8d1c12c9f8201","lessThan":"4336e3f47d9d516441066e9a65eaf076790d8d45","status":"affected","versionType":"git"},{"version":"bf635681c906ad056d1fda325de8d1c12c9f8201","lessThan":"c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/time/posix-cpu-timers.c"],"versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9971dac1a77845ff467146915fcbb9170f6a8209"},{"url":"https://git.kernel.org/stable/c/4336e3f47d9d516441066e9a65eaf076790d8d45"},{"url":"https://git.kernel.org/stable/c/c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd"}],"title":"posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list","x_generator":{"engine":"bippy-1.2.0"}}}}