CVE-2024-35887

Updated: 2026-02-27 01:44:59.556379

Description:

In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer handler is running, the ax25_ds_del_timer() that calls del_timer() in it will return directly. As a result, the use-after-free bugs could happen, one of the scenarios is shown below: (Thread 1) | (Thread 2) | ax25_ds_timeout() ax25_dev_device_down() | ax25_ds_del_timer() | del_timer() | ax25_dev_put() //FREE | | ax25_dev-> //USE In order to mitigate bugs, when the device is detaching, use timer_shutdown_sync() to stop the timer.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Not Vulnerable 2025-01-22 01:31:37 Not affected: CVE-2024-35887 is limited to the AX.25 amateur‑radio networking stack and requires t...
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 Not affected: This flaw exists only in the Linux AX.25 amateur‑radio networking stack and is reach...
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 Not affected: This flaw exists only in the optional AX.25 amateur‑radio networking subsystem and i...
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-01-22 01:31:34 CVE-2024-35887 only affects the Linux AX.25 amateur‑radio networking stack, and the vulnerable cod...
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 CVE-2024-35887 only affects the Linux AX.25 amateur‑radio networking stack, and the vulnerable cod...
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 CVE-2024-35887 only affects the Linux AX.25 amateur‑radio networking stack, and the vulnerable cod...
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 Not affected: This flaw exists only in the optional AX.25 amateur‑radio networking subsystem and i...
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 Not affected: This flaw exists only in the Linux AX.25 amateur‑radio networking stack and is reach...
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-01-28 02:26:13 Not affected: This flaw exists only in the optional AX.25 amateur‑radio networking subsystem and i...
Total: 14