CVE-2025-71086None▾ SunlitIn the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_device() rose_kill_by_device() collects sockets into a local array[] and then iterates over them to disconnect socke…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.1%
0.1% → 0.1%
In the Linux kernel, the following vulnerability has been resolved:
net: rose: fix invalid array index in rose_kill_by_device()
rose_kill_by_device() collects sockets into a local array[] and then iterates over them to disconnect sockets bound to a device being brought down.
The loop mistakenly indexes array[cnt] instead of array[i]. For cnt < ARRAY_SIZE(array), this reads an uninitialized entry; for cnt == ARRAY_SIZE(array), it is an out-of-bounds read. Either case can lead to an invalid socket pointer dereference and also leaks references taken via sock_hold().
Fix the index to use i.
Linux >= 12e5a4719c99d7f4104e7e962393dfb8baa1c591 < 819fb41ae54960f66025802400c9d3935eef4042Linux >= c0e527c532a07556ca44642f5873b002c44da22c < ed2639414d43ba037f798eaf619e878309310451Linux >= 3e0d1585799d8a991eba9678f297fd78d9f1846e < 1418c12cd3bba79dc56b57b61c99efe40f579981Linux >= ffced26692f83212aa09d0ece0213b23cc2f611d < 9f6185a32496834d6980b168cffcccc2d6b17280Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < b409ba9e1e63ccf3ab4cc061e33c1f804183543eLinux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 92d900aac3a5721fb54f3328f1e089b44a861c38Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 6595beb40fb0ec47223d3f6058ee40354694c8e4Linux bd7de4734535140fda33240c2335a07fdab6f88eLinux b10265532df7bc3666bc53261b7f03f0fd14b1c9Linux >= 5.10.206 < 5.10.248Linux >= 5.15.146 < 5.15.198Linux >= 6.1.70 < 6.1.160Linux >= 6.6.9 < 6.6.120Linux >= 4.19.304 < 4.20Linux >= 5.4.266 < 5.5Linux 6.7Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68286NoneIn the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() /…
CVE-2026-68337NoneIn the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri()…
CVE-2026-68287High· 7.5In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attri…
CVE-2026-68288NoneIn the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to a…
CVE-2026-68289NoneIn the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buf…
CVE-2026-68303NoneIn the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions