cbcvebase.
CVE-2025-71086
published 2026-01-13

CVE-2025-71086: In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_device() rose_kill_by_device() collects…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_device() rose_kill_by_device() collects sockets into a local array[] and then iterates over them to disconnect sockets bound to a device being brought down. The loop mistakenly indexes array[cnt] instead of array[i]. For cnt < ARRAY_SIZE(array), this reads an uninitialized entry; for cnt == ARRAY_SIZE(array), it is an out-of-bounds read. Either case can lead to an invalid socket pointer dereference and also leaks references taken via sock_hold(). Fix the index to use i.

Affected

76 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 12e5a4719c99d7f4104e7e962393dfb8baa1c591 < 819fb41ae54960f66025802400c9d3935eef4042819fb41ae54960f66025802400c9d3935eef4042
linuxlinux>= 3e0d1585799d8a991eba9678f297fd78d9f1846e < 1418c12cd3bba79dc56b57b61c99efe40f5799811418c12cd3bba79dc56b57b61c99efe40f579981
linuxlinux>= 4.19.304 < 4.204.20
linuxlinux>= 5.10.206 < 5.10.2485.10.248
linuxlinux>= 5.15.146 < 5.15.1985.15.198
linuxlinux>= 5.4.266 < 5.55.5
linuxlinux>= 6.1.70 < 6.1.1606.1.160
linuxlinux>= 6.6.9 < 6.6.1206.6.120
linuxlinux>= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < b409ba9e1e63ccf3ab4cc061e33c1f804183543eb409ba9e1e63ccf3ab4cc061e33c1f804183543e
linuxlinux>= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 92d900aac3a5721fb54f3328f1e089b44a861c3892d900aac3a5721fb54f3328f1e089b44a861c38
linuxlinux>= 64b8bc7d5f1434c636a40bdcfcd42b278d1714be < 6595beb40fb0ec47223d3f6058ee40354694c8e46595beb40fb0ec47223d3f6058ee40354694c8e4
linuxlinux>= c0e527c532a07556ca44642f5873b002c44da22c < ed2639414d43ba037f798eaf619e878309310451ed2639414d43ba037f798eaf619e878309310451
linuxlinux>= ffced26692f83212aa09d0ece0213b23cc2f611d < 9f6185a32496834d6980b168cffcccc2d6b172809f6185a32496834d6980b168cffcccc2d6b17280
linuxlinux_kernel< 6.18.46.18.4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.