CVE-2024-35887

ax25: fix use-after-free bugs caused by ax25_ds_del_timer

References

Notes

 carnil> Introduced in 1da177e4c3f4 ("Linux-2.6.12-rc2"). Vulnerable versions:
 carnil> 2.6.12-rc2^0.

Bugs

Status

Branch Status
upstream released (6.9-rc3) [fd819ad3ecf6f3c232a06b27423ce9ed8c20da89]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.8-upstream-stable released (6.8.5) [c6a368f9c7af4c14b14d390c2543af8001c9bdb9]
6.6-upstream-stable released (6.6.26) [74204bf9050f7627aead9875fe4e07ba125cb19b]
6.1-upstream-stable needed
5.10-upstream-stable needed
sid released (6.8.9-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security needed
5.10-bullseye-security needed