
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.
This repository only contains the proof-of-concept that triggers the vulnerability.
I have since written a full exploit for this vulnerability. You can find the details in the link below.
https://github.com/farazsth98/chronomaly

The PoC really depends on how CPU time is consumed by the getpid system call.
To that end, I've ensured to make the PoC as system-agnostic as possible - that is, it should work on your system even if the getpid system call uses up drastically more / less time than on my system.
This is a PoC for CVE-2025-38352, a race condition vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.
It was written for LTS 6.12.33, and requires CONFIG_POSIX_CPU_TIMERS_TASK_WORK to be turned off in the kernel config. Additionally, I also turned on full preemption (CONFIG_PREEMPT=y) as that's what the Android kernel uses.
Once the race is won, it leads to a use-after-free of a struct k_itimer.
For more information on setting up the testing environment, please refer to the blog post linked above, specifically the "Testing Environment TL;DR section".
NOTE: No patches are required for this PoC to work (putting this here because my last PoC kind of needed a 500ms mdelay 😅).
The PoC has always triggered for me within 100 retries (it's never actually reached more than 60 retries). Reliability can be improved in a few places IMO, but I'll work on that later.
The profiler_patch.diff file contains a patch to apply some profiling code to handle_posix_cpu_timers(). It is useful for figuring out how to extend the race window, as it prints out the amount of execution time used by the firing list iteration here.
Compile with the provided Makefile and just run it with /poc.
If you want to run the profiler, compile it the same way as the PoC.
Hit me up on Twitter or wherever else if you have any questions.