CVE-2024-35887

Updated: 2026-02-27 01:44:59.556379

Description:

In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer handler is running, the ax25_ds_del_timer() that calls del_timer() in it will return directly. As a result, the use-after-free bugs could happen, one of the scenarios is shown below: (Thread 1) | (Thread 2) | ax25_ds_timeout() ax25_dev_device_down() | ax25_ds_del_timer() | del_timer() | ax25_dev_put() //FREE | | ax25_dev-> //USE In order to mitigate bugs, when the device is detaching, use timer_shutdown_sync() to stop the timer.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

RHEL 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-05-28 00:25:12 CVE-2024-35887 is confined to the Linux AX.25 amateur‑radio networking stack and is only reachable...
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2025:1738696174 2025-02-05 02:15:31
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2025:1738957378 2025-02-07 22:55:16
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Released CLSA-2025:1738852812 2025-02-07 06:35:56
Total: 14