# CVE-2024-35887

## Summary

- **CVE ID:** CVE-2024-35887
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** May 19, 2024
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ax25: fix use-after-free bugs caused by ax25_ds_del_timer

When the ax25 device is detaching, the ax25_dev_device_down()
calls ax25_ds_del_timer() to cleanup the slave_timer. When
the timer handler is running, the ax25_ds_del_timer() that
calls del_timer() in it will return directly. As a result,
the use-after-free bugs could happen, one of the scenarios
is shown below:

      (Thread 1)          |      (Thread 2)
                          | ax25_ds_timeout()
ax25_dev_device_down()    |
  ax25_ds_del_timer()     |
    del_timer()           |
  ax25_dev_put() //FREE   |
                          |  ax25_dev-> //USE

In order to mitigate bugs, when the device is detaching, use
timer_shutdown_sync() to stop the timer.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (2.6.12)
- Linux — Linux (0)
- Linux — Linux (6.6.26)
- Linux — Linux (6.8.5)
- Linux — Linux (6.9)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)

## References

- [CNA](https://git.kernel.org/stable/c/74204bf9050f7627aead9875fe4e07ba125cb19b)
- [CNA](https://git.kernel.org/stable/c/c6a368f9c7af4c14b14d390c2543af8001c9bdb9)
- [CNA](https://git.kernel.org/stable/c/fd819ad3ecf6f3c232a06b27423ce9ed8c20da89)
- [CNA](https://git.kernel.org/stable/c/28f2d36ac52225a13e020c2589833f1816a0cfc6)
- [CNA](https://git.kernel.org/stable/c/8a912ef5b7c5d14fb41b9a7935d1df5bb87058bf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 27.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._