---
id: CVE-2025-71086
title: 'net: rose: fix invalid array index in rose_kill_by_device()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: rose: fix invalid array index in rose_kill_by_device()

  rose_kill_by_device() collects sockets into a local array[] and then
  iterates over them to disconnect socke…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 12e5a4719c99d7f4104e7e962393dfb8baa1c591 <
    819fb41ae54960f66025802400c9d3935eef4042
  - >-
    Linux >= c0e527c532a07556ca44642f5873b002c44da22c <
    ed2639414d43ba037f798eaf619e878309310451
  - >-
    Linux >= 3e0d1585799d8a991eba9678f297fd78d9f1846e <
    1418c12cd3bba79dc56b57b61c99efe40f579981
  - >-
    Linux >= ffced26692f83212aa09d0ece0213b23cc2f611d <
    9f6185a32496834d6980b168cffcccc2d6b17280
  - >-
    Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be <
    b409ba9e1e63ccf3ab4cc061e33c1f804183543e
  - >-
    Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be <
    92d900aac3a5721fb54f3328f1e089b44a861c38
  - >-
    Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be <
    6595beb40fb0ec47223d3f6058ee40354694c8e4
  - Linux bd7de4734535140fda33240c2335a07fdab6f88e
  - Linux b10265532df7bc3666bc53261b7f03f0fd14b1c9
  - Linux >= 5.10.206 < 5.10.248
  - Linux >= 5.15.146 < 5.15.198
  - Linux >= 6.1.70 < 6.1.160
  - Linux >= 6.6.9 < 6.6.120
  - Linux >= 4.19.304 < 4.20
  - Linux >= 5.4.266 < 5.5
  - Linux 6.7
published: '2026-01-13'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:43:46.228Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-71086'
references:
  - url: 'https://git.kernel.org/stable/c/819fb41ae54960f66025802400c9d3935eef4042'
  - url: 'https://git.kernel.org/stable/c/ed2639414d43ba037f798eaf619e878309310451'
  - url: 'https://git.kernel.org/stable/c/1418c12cd3bba79dc56b57b61c99efe40f579981'
  - url: 'https://git.kernel.org/stable/c/9f6185a32496834d6980b168cffcccc2d6b17280'
  - url: 'https://git.kernel.org/stable/c/b409ba9e1e63ccf3ab4cc061e33c1f804183543e'
  - url: 'https://git.kernel.org/stable/c/92d900aac3a5721fb54f3328f1e089b44a861c38'
  - url: 'https://git.kernel.org/stable/c/6595beb40fb0ec47223d3f6058ee40354694c8e4'
tags:
  - cve.org
epss: 0.00141
epssPercentile: 0.03775
ingestedAt: '2026-09-08T15:33:26.995Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: rose: fix invalid array index in rose_kill_by_device()

rose_kill_by_device() collects sockets into a local array[] and then
iterates over them to disconnect sockets bound to a device being brought
down.

The loop mistakenly indexes array[cnt] instead of array[i]. For cnt <
ARRAY_SIZE(array), this reads an uninitialized entry; for cnt ==
ARRAY_SIZE(array), it is an out-of-bounds read. Either case can lead to
an invalid socket pointer dereference and also leaks references taken
via sock_hold().

Fix the index to use i.

## Affected

- `Linux >= 12e5a4719c99d7f4104e7e962393dfb8baa1c591 < 819fb41ae54960f66025802400c9d3935eef4042`
- `Linux >= c0e527c532a07556ca44642f5873b002c44da22c < ed2639414d43ba037f798eaf619e878309310451`
- `Linux >= 3e0d1585799d8a991eba9678f297fd78d9f1846e < 1418c12cd3bba79dc56b57b61c99efe40f579981`
- `Linux >= ffced26692f83212aa09d0ece0213b23cc2f611d < 9f6185a32496834d6980b168cffcccc2d6b17280`
- `Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < b409ba9e1e63ccf3ab4cc061e33c1f804183543e`
- `Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 92d900aac3a5721fb54f3328f1e089b44a861c38`
- `Linux >= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 6595beb40fb0ec47223d3f6058ee40354694c8e4`
- `Linux bd7de4734535140fda33240c2335a07fdab6f88e`
- `Linux b10265532df7bc3666bc53261b7f03f0fd14b1c9`
- `Linux >= 5.10.206 < 5.10.248`
- `Linux >= 5.15.146 < 5.15.198`
- `Linux >= 6.1.70 < 6.1.160`
- `Linux >= 6.6.9 < 6.6.120`
- `Linux >= 4.19.304 < 4.20`
- `Linux >= 5.4.266 < 5.5`
- `Linux 6.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
