In runposixcpu_timers of posix-cpu-timers.c, there is a possible way to trigger a use-after-free on a sigqueue object due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "signature_version": "v1", "source": "https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb", "id": "ASB-A-425282960-0d6867e2", "target": { "file": "kernel/time/posix-cpu-timers.c" }, "signature_type": "Line", "digest": { "line_hashes": [ "239550998081870972127451971872312053997", "147150368589273284825147366725515272174", "82833152002525841078026884179897054603" ], "threshold": 0.9 }, "deprecated": false }, { "signature_version": "v1", "source": "https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83", "id": "ASB-A-425282960-553e0dda", "target": { "file": "kernel/time/posix-cpu-timers.c" }, "signature_type": "Line", "digest": { "line_hashes": [ "239550998081870972127451971872312053997", "147150368589273284825147366725515272174", "82833152002525841078026884179897054603" ], "threshold": 0.9 }, "deprecated": false }, { "signature_version": "v1", "source": "https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83", "id": "ASB-A-425282960-d6dfad21", "target": { "function": "run_posix_cpu_timers", "file": "kernel/time/posix-cpu-timers.c" }, "signature_type": "Function", "digest": { "length": 154.0, "function_hash": "328631927418429210242873994005901180136" }, "deprecated": false }, { "signature_version": "v1", "source": "https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb", "id": "ASB-A-425282960-e83512d2", "target": { "function": "run_posix_cpu_timers", "file": "kernel/time/posix-cpu-timers.c" }, "signature_type": "Function", "digest": { "length": 154.0, "function_hash": "328631927418429210242873994005901180136" }, "deprecated": false } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb", "https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83" ], "severity": "High", "types": [ "EoP" ], "spl": "2025-09-05" }