The same effect can be seen in another 25-row mode, 6. HIMEM is set at 24576, which is 8K below 32768, but the screen actually only takes up 40 columns x 8 bytes per column x 25 rows = 8,000 bytes, so in this case we have 192 bytes free above the screen memory below the top of user memory.
I've calculated this as &7F40, and poked TIME$ in, even though there is considerably more space available this time, but it works, reads back and doesn't corrupt the screen.