In runposixcpu_timers of posix-cpu-timers.c, there is a possible way to trigger a use-after-free on a sigqueue object due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "id": "ASB-A-425282960-0d6867e2", "digest": { "threshold": 0.9, "line_hashes": [ "239550998081870972127451971872312053997", "147150368589273284825147366725515272174", "82833152002525841078026884179897054603" ] }, "source": "https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb", "target": { "file": "kernel/time/posix-cpu-timers.c" }, "signature_version": "v1" }, { "deprecated": false, "signature_type": "Line", "id": "ASB-A-425282960-553e0dda", "digest": { "threshold": 0.9, "line_hashes": [ "239550998081870972127451971872312053997", "147150368589273284825147366725515272174", "82833152002525841078026884179897054603" ] }, "source": "https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83", "target": { "file": "kernel/time/posix-cpu-timers.c" }, "signature_version": "v1" }, { "deprecated": false, "signature_type": "Function", "id": "ASB-A-425282960-d6dfad21", "digest": { "length": 154.0, "function_hash": "328631927418429210242873994005901180136" }, "source": "https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83", "target": { "function": "run_posix_cpu_timers", "file": "kernel/time/posix-cpu-timers.c" }, "signature_version": "v1" }, { "deprecated": false, "signature_type": "Function", "id": "ASB-A-425282960-e83512d2", "digest": { "length": 154.0, "function_hash": "328631927418429210242873994005901180136" }, "source": "https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb", "target": { "function": "run_posix_cpu_timers", "file": "kernel/time/posix-cpu-timers.c" }, "signature_version": "v1" } ], "spl": "2025-09-05", "fixes": [ "https://android.googlesource.com/kernel/common/+/157f357d50b5038e5eaad0b2b438f923ac40afeb", "https://android.googlesource.com/kernel/common/+/1bf1aa362e6b9573a310fcd14f35bc875b42ba83" ], "types": [ "EoP" ], "severity": "High" }