PT-2024-8341 · Linux+9 · Linux Kernel+9

Josef Bacik

·

Published

2024-03-25

·

Updated

2025-09-29

·

CVE-2024-35910

CVSS v3.1

5.8

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The vulnerability is related to the improper termination of timers for kernel sockets in the Linux kernel. When TCP sockets are closed, the function inet csk clear xmit timers() is called to stop the timers. However, this function can be called from any context, including when the socket lock is held, which can lead to ongoing timers finishing much later. For kernel sockets, this can cause the netns to be freed before the timer can complete, because kernel sockets do not hold a reference on the netns. The patch adds a new function inet csk clear xmit timers sync() that uses sk stop timer sync() to ensure all timers are terminated before the kernel socket is released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5101
ALSA-2024:5102
ALSA-2025_16880
BDU:2024-09897
CESA-2024_5101
CESA-2024_5102
CVE-2024-35910
DLA-3840-1
DLA-3842-1
INFSA-2024_5101
INFSA-2024_5102
OESA-2024-1736
OESA-2024-1737
OESA-2024-1738
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024:5255
RHSA-2024_5101
RHSA-2024_5102
RLSA-2024:5101
RLSA-2024:5102
RXSA-2024:5101
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:1293-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
SUSE-SU-2025_1293-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu