The Year 2038 Problem

Days
Hrs
Min
Sec

until Tuesday, January 19, 2038 · 03:14:08 UTC
that's your local time

Live · The counter

Every second, one more

Unix systems keep time as a single number: the seconds elapsed since midnight UTC on January 1, 1970.1 Here it is right now, as a signed 32-bit integer holds it.

Decimal
 
Hex
 
Headroom left
 
↑ bit 31: the sign bit. When it flips, time goes negative. bit 0 ↑
1970-01-012038-01-19

01 · The problem

What is the Year 2038 problem?

In C, and in the operating systems written in it, time is stored in a type called time_t. For decades, 32-bit Unix systems were built using a signed 32-bit integer for time_t.2 It can count to 2,147,483,647 (231 − 1) and no further. Even today, on 32-bit Linux systems using the standard GNU C library, programs get a 32-bit time_t unless they're built with _TIME_BITS=64.3

Counting one per second from 1970, that ceiling arrives at 03:14:07 UTC on January 19, 2038. One second later the count doesn't reach 2,147,483,648. It wraps to the most negative value the type can hold, and every program reading it believes it's Friday, December 13, 1901.

Last good second
2,147,483,647
0111 1111 1111 1111 1111 1111 1111 1111
2038-01-19 03:14:07 UTC
+1 second
→
What a 32-bit clock reads next
−2,147,483,648
1000 0000 0000 0000 0000 0000 0000 0000
1901-12-13 20:45:52 UTC

Try it in your browser console:

new Date((2**31 - 1) * 1000).toISOString()  // '2038-01-19T03:14:07.000Z'
new Date(-(2**31) * 1000).toISOString()     // '1901-12-13T20:45:52.000Z'
2**63 / 31556952                            // about 292 billion years

Picture a car odometer rolling over from 99999 to 00000, except this one rolls over to a negative number, and the software reading it can't tell anything went wrong. Timeouts land in the past, which is exactly what froze AOLserver in 2006.4 Any duration measured across the boundary comes out wrong by about 136 years.

The fix is known: make time_t 64 bits wide.2 A signed 64-bit count of seconds lasts about 292 billion years. The hard part is finding every place the 32-bit assumption hides, and reaching the devices that can't be updated.

02 · The damage

What breaks

The risk is concentrated in systems that are 32-bit, old, or store time somewhere other than memory: on disk, in a database, or on the wire.

Highest risk

Embedded & industrial systems

Controllers, PLCs, routers, medical devices, in-car electronics. In industry, “many facilities in the continuous process industries are still looking at 20 to 30 years as a life cycle for their equipment.”5 Systems deployed today will still be running in 2038.2

Already shipping

32-bit Linux

Linux 5.6, released in March 2020, was the first kernel that could serve as a base for a 32-bit system designed to run past 2038.6,7 The GNU C library added opt-in 64-bit time_t in version 2.34, in August 2021.3

At rest

File systems

Timestamps are part of the disk format. ext4 with 128-byte inodes stores 32-bit seconds that overflow in January 2038.8 XFS needs its bigtime feature, added in Linux 5.10, to get past 2038.9 A fixed kernel can't help if the bytes on disk can't hold the date.

At rest

Databases

MySQL's TIMESTAMP type ends at 2038-01-19 03:14:07 UTC.10 Epoch seconds stored in a signed 4-byte INT column hit the same ceiling: 2,147,483,647.11

On the wire

File formats & protocols

Time is baked into binary formats and network protocols. The Network Time Protocol's timestamp has a 32-bit seconds field that wraps in 2036.12 Widening a field means changing the format, and every program that reads it.

Hits early

Anything that looks ahead

Software that calculates future dates breaks as soon as the result crosses 2038. Loan terms, certificates and long timeouts all qualify. AOLserver hit this 32 years early.4

It has already happened. In May 2006, AOLserver installations started hanging: a database timeout configured as one billion seconds, added to the current time, overflowed 32-bit time.4 On January 1, 2022, on-premises Exchange Server 2016 and 2019 stopped delivering email because a date value, 2,201,010,001, no longer fit in a signed 32-bit integer. It was nicknamed “Y2K22.”13,14

03 · Context

Computers keep running out of time

2038 isn't the first clock rollover, and it won't be the last. Every fixed-width counter has an end date.

  1. 1999-08-22
    GPS week rollover. GPS counts weeks in a 10-bit field, which resets to zero every 1,024 weeks.15 Receivers not built for it read the date as January 6, 1980.16
  2. 2000-01-01
    Y2K. Two-digit years roll over to “00.” Fixing it cost an estimated $300–600 billion worldwide, and it worked.17,18,19
  3. 2006-05
    AOLserver. A one-billion-second timeout overflows 32-bit time, 32 years early.4
  4. 2019-04-06
    Second GPS rollover. Another 1,024 weeks, another reset.15
  5. 2020-03
    Linux 5.6. 32-bit Linux systems can finally be built to run past 2038.6
  6. 2022-01-01
    “Y2K22.” A date value overflows a signed 32-bit integer in Microsoft Exchange.13
  7. 2036-02-07
    NTP era rollover. At 06:28:16 UTC, the Network Time Protocol's 32-bit seconds count, which started in 1900, wraps around.12
  8. 2038-01-19
    The Epochalypse. Signed 32-bit Unix time overflows at 03:14:08 UTC.
  9. 2106-02-07
    Unsigned 32-bit Unix time. Systems that “fixed” 2038 by going unsigned bought 68 more years.

04 · The last time

Remember Y2K?

The closest thing we have to a dress rehearsal. It's remembered as a false alarm. It wasn't.17,19

The bug

To save memory, programmers stored years as two digits: “65” meant 1965.17 Decades later, software from bank records to telephone exchanges to aircraft control still worked that way, and would read “00” as 1900.16

The hysteria

People stockpiled food, water, generators and firearms, and feared plane crashes and failing power grids.19 Evangelical broadcasters warned of disaster, and Jerry Falwell sold a Y2K survival video.20 Leonard Nimoy hosted one too: the Y2K Family Survival Guide.21 The United States and Russia staffed a joint center in Colorado Springs to monitor missile launches through the rollover.22 The Federal Reserve ordered extra currency and built its cash inventory to over $200 billion in case people rushed to withdraw it.23,24

The fix

Behind the noise, the work was unglamorous. Organizations expanded years to four digits or, where they couldn't, used “windowing,” for example reading 00–50 as 2000–2050.17 Projects ran for years.19 The U.S. created a President's Council on Year 2000 Conversion25 and a Senate special committee.26 Worldwide cost estimates run from about $300 billion to $600 billion.17,18

What actually happened

Midnight came and the lights stayed on. The failures were real but small. The U.S. Naval Observatory's website gave the year as “19100” for 45 minutes.27 Japan's Shika nuclear plant had problems with its radiation-monitoring system, with no effect on power generation.28 A video store in Colonie, New York, billed a customer $91,250 for a tape it calculated was 100 years late.29 The worst damage surfaced later: in Sheffield, England, a hospital system miscalculated mothers' ages, and more than 150 pregnant women received incorrect Down syndrome screening results.30

The preparedness paradox. Because the fix worked, Y2K became a punch line.19 That makes 2038 harder: the people who'd need to fund the fix remember the last one as a false alarm.

05 · Lessons learned

Why 2038 is harder

Y2K had a visible bug, a famous deadline and hundreds of billions of dollars behind it.17,18 2038 has fewer of those advantages.

Y2K2038
The bugYears stored as two digits17Seconds stored in a signed 32-bit binary integer2
Where it hidApplication code and stored recordsKernels, C libraries, firmware, disk formats and protocols2,8,12
Finding itSearch code and data for date fieldsTrace a type through compiled binaries, libraries and on-disk structures
Fixing itWiden fields, or window the years17Rebuild with 64-bit time_t, which changes the ABI,2 migrate stored data, and replace hardware that can't be reflashed

What Y2K taught us

  • Inventory first. You can't fix what you don't know you run, especially embedded devices nobody remembers installing.
  • Start early. Y2K projects took years.19 Devices installed today will still be in service in 2038.2
  • Talk about it calmly. The alarm made Y2K easy to dismiss afterward.19 Specific and boring gets things fixed.

If you write software

  • Use 64-bit time everywhere. On 32-bit glibc, build with -D_TIME_BITS=64 -D_FILE_OFFSET_BITS=64.3
  • Audit your schemas. Look for INT epoch columns and MySQL TIMESTAMP; prefer BIGINT or DATETIME.10,11
  • Check your formats. Any binary file or protocol with a 4-byte time field needs a migration plan.
  • Fake the clock. libfaketime lets you run a program in 2038 without touching the system clock.31

Every claim on this page is cited. See all sources →