---
id: CVE-2024-35887
title: 'ax25: fix use-after-free bugs caused by ax25_ds_del_timer'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ax25: fix use-after-free bugs caused by ax25_ds_del_timer

  When the ax25 device is detaching, the ax25_dev_device_down()
  calls ax25_ds_del_timer() to cleanup the slave_…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    28f2d36ac52225a13e020c2589833f1816a0cfc6
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    8a912ef5b7c5d14fb41b9a7935d1df5bb87058bf
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    74204bf9050f7627aead9875fe4e07ba125cb19b
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    c6a368f9c7af4c14b14d390c2543af8001c9bdb9
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    fd819ad3ecf6f3c232a06b27423ce9ed8c20da89
  - Linux 2.6.12
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-05-29T18:31:26.964668Z'
published: '2024-05-19'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:57:42.938Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2024-35887'
references:
  - url: 'https://git.kernel.org/stable/c/28f2d36ac52225a13e020c2589833f1816a0cfc6'
  - url: 'https://git.kernel.org/stable/c/8a912ef5b7c5d14fb41b9a7935d1df5bb87058bf'
  - url: 'https://git.kernel.org/stable/c/74204bf9050f7627aead9875fe4e07ba125cb19b'
  - url: 'https://git.kernel.org/stable/c/c6a368f9c7af4c14b14d390c2543af8001c9bdb9'
  - url: 'https://git.kernel.org/stable/c/fd819ad3ecf6f3c232a06b27423ce9ed8c20da89'
tags:
  - cve.org
epss: 0.00341
epssPercentile: 0.24966
ingestedAt: '2026-09-14T15:23:07.460Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ax25: fix use-after-free bugs caused by ax25_ds_del_timer

When the ax25 device is detaching, the ax25_dev_device_down()
calls ax25_ds_del_timer() to cleanup the slave_timer. When
the timer handler is running, the ax25_ds_del_timer() that
calls del_timer() in it will return directly. As a result,
the use-after-free bugs could happen, one of the scenarios
is shown below:

      (Thread 1)          |      (Thread 2)
                          | ax25_ds_timeout()
ax25_dev_device_down()    |
  ax25_ds_del_timer()     |
    del_timer()           |
  ax25_dev_put() //FREE   |
                          |  ax25_dev-> //USE

In order to mitigate bugs, when the device is detaching, use
timer_shutdown_sync() to stop the timer.

## Affected

- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 28f2d36ac52225a13e020c2589833f1816a0cfc6`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8a912ef5b7c5d14fb41b9a7935d1df5bb87058bf`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 74204bf9050f7627aead9875fe4e07ba125cb19b`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c6a368f9c7af4c14b14d390c2543af8001c9bdb9`
- `Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fd819ad3ecf6f3c232a06b27423ce9ed8c20da89`
- `Linux 2.6.12`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
