{"id":"CVE-2025-71086","title":"net: rose: fix invalid array index in rose_kill_by_device()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: fix invalid array index in rose_kill_by_device()\n\nrose_kill_by_device() collects sockets into a local array[] and then\niterates over them to disconnect socke…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 12e5a4719c99d7f4104e7e962393dfb8baa1c591 < 819fb41ae54960f66025802400c9d3935eef4042","Linux >= c0e527c532a07556ca44642f5873b002c44da22c < ed2639414d43ba037f798eaf619e878309310451","Linux >= 3e0d1585799d8a991eba9678f297fd78d9f1846e < 1418c12cd3bba79dc56b57b61c99efe40f579981","Linux >= ffced26692f83212aa09d0ece0213b23cc2f611d < 9f6185a32496834d6980b168cffcccc2d6b17280","Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < b409ba9e1e63ccf3ab4cc061e33c1f804183543e","Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 92d900aac3a5721fb54f3328f1e089b44a861c38","Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 6595beb40fb0ec47223d3f6058ee40354694c8e4","Linux bd7de4734535140fda33240c2335a07fdab6f88e","Linux b10265532df7bc3666bc53261b7f03f0fd14b1c9","Linux >= 5.10.206 < 5.10.248","Linux >= 5.15.146 < 5.15.198","Linux >= 6.1.70 < 6.1.160","Linux >= 6.6.9 < 6.6.120","Linux >= 4.19.304 < 4.20","Linux >= 5.4.266 < 5.5","Linux 6.7"],"published":"2026-01-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:43:46.228Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-71086","references":[{"url":"https://git.kernel.org/stable/c/819fb41ae54960f66025802400c9d3935eef4042"},{"url":"https://git.kernel.org/stable/c/ed2639414d43ba037f798eaf619e878309310451"},{"url":"https://git.kernel.org/stable/c/1418c12cd3bba79dc56b57b61c99efe40f579981"},{"url":"https://git.kernel.org/stable/c/9f6185a32496834d6980b168cffcccc2d6b17280"},{"url":"https://git.kernel.org/stable/c/b409ba9e1e63ccf3ab4cc061e33c1f804183543e"},{"url":"https://git.kernel.org/stable/c/92d900aac3a5721fb54f3328f1e089b44a861c38"},{"url":"https://git.kernel.org/stable/c/6595beb40fb0ec47223d3f6058ee40354694c8e4"}],"tags":["cve.org"],"epss":0.00141,"epssPercentile":0.03775,"ingestedAt":"2026-09-08T15:33:26.995Z","slug":"CVE-2025-71086","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: fix invalid array index in rose_kill_by_device()\n\nrose_kill_by_device() collects sockets into a local array[] and then\niterates over them to disconnect sockets bound to a device being brought\ndown.\n\nThe loop mistakenly indexes array[cnt] instead of array[i]. For cnt <\nARRAY_SIZE(array), this reads an uninitialized entry; for cnt ==\nARRAY_SIZE(array), it is an out-of-bounds read. Either case can lead to\nan invalid socket pointer dereference and also leaks references taken\nvia sock_hold().\n\nFix the index to use i.\n\n## Affected\n\n- `Linux >= 12e5a4719c99d7f4104e7e962393dfb8baa1c591 < 819fb41ae54960f66025802400c9d3935eef4042`\n- `Linux >= c0e527c532a07556ca44642f5873b002c44da22c < ed2639414d43ba037f798eaf619e878309310451`\n- `Linux >= 3e0d1585799d8a991eba9678f297fd78d9f1846e < 1418c12cd3bba79dc56b57b61c99efe40f579981`\n- `Linux >= ffced26692f83212aa09d0ece0213b23cc2f611d < 9f6185a32496834d6980b168cffcccc2d6b17280`\n- `Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < b409ba9e1e63ccf3ab4cc061e33c1f804183543e`\n- `Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 92d900aac3a5721fb54f3328f1e089b44a861c38`\n- `Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 6595beb40fb0ec47223d3f6058ee40354694c8e4`\n- `Linux bd7de4734535140fda33240c2335a07fdab6f88e`\n- `Linux b10265532df7bc3666bc53261b7f03f0fd14b1c9`\n- `Linux >= 5.10.206 < 5.10.248`\n- `Linux >= 5.15.146 < 5.15.198`\n- `Linux >= 6.1.70 < 6.1.160`\n- `Linux >= 6.6.9 < 6.6.120`\n- `Linux >= 4.19.304 < 4.20`\n- `Linux >= 5.4.266 < 5.5`\n- `Linux 6.7`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}