ThreatCluster

Multiple CVEs Addressing POSIX CPU Timer Vulnerabilities Published

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 79% similarity 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities related to POSIX CPU timers have been published, affecting systems that utilize these timers. CVE-2022-2585, published on January 8, 2024, involves a use-after-free issue when executing from a non-leader thread. CVE-2025-38352, published on July 22, 2025, addresses a race condition between timer handling functions.

ThreatCluster AI How this analysis works

Timeline

2024-01-08
CVE-2022-2585 published
2024-12-16
First public PoC for CVE-2025-38352 released
2025-07-22
CVE-2025-38352 published
2025-09-04
CVE-2025-38352 added to CISA KEV (active exploitation)

Community

Browse all →