CVE-2025-38377 Details
Description
In the Linux kernel, the following vulnerability has been resolved: rose: fix dangling neighbour pointers in rose_rt_device_down() There are two bugs in rose_rt_device_down() that can cause use-after-free: 1. The loop bound `t->count` is modified within the loop, which can cause the loop to terminate early and miss some entries. 2. When removing an entry from the neighbour array, the subsequent entries are moved up to fill the gap, but the loop index `i` is still incremented, causing the next entry to be skipped. For example, if a node has three neighbours (A, A, B) with count=3 and A is being removed, the second A is not checked. i=0: (A, A, B) -> (A, B) with count=2 ^ checked i=1: (A, B) -> (A, B) with count=2 ^ checked (B, not A!) i=2: (doesn't occur because i < count is false) This leaves the second A in the array with count=2, but the rose_neigh structure has been freed. Code that accesses these entries assumes that the first `count` entries are valid pointers, causing a use-after-free when it accesses the dangling pointer. Fix both issues by iterating over the array in reverse order with a fixed loop bound. This ensures that all entries are examined and that the removal of an entry doesn't affect subsequent iterations.
A use-after-free vulnerability has been identified in the Linux kernel's handling of neighbor pointers within the ROSE protocol. This issue arises in the function 'rose_rt_device_down()', where two bugs can lead to improper memory management. First, the loop that processes neighbor entries can terminate prematurely, causing some entries to be overlooked. Second, when an entry is removed, the remaining entries shift up to fill the gap, but the loop index continues to advance, resulting in skipped entries. This mismanagement can leave dangling pointers that, when accessed, cause a use-after-free condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2b952dbb32fef835756f07ff0cd77efbb836dfea | kernel.org | Patch |
| https://git.kernel.org/stable/c/2c6c82ee074bfcfd1bc978ec45bfea37703d840a | kernel.org | Patch |
| https://git.kernel.org/stable/c/34a500caf48c47d5171f4aa1f237da39b07c6157 | kernel.org | Patch |
| https://git.kernel.org/stable/c/446ac00b86be1670838e513b643933d78837d8db | kernel.org | Patch |
| https://git.kernel.org/stable/c/7a1841c9609377e989ec41c16551309ce79c39e4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/94e0918e39039c47ddceb609500817f7266be756 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b6b232e16e08c6dc120672b4753392df0d28c1b4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fe62a35fb1f77f494ed534fc69a9043dc5a30ce1 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html | CVE | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.13, < 5.4.296 >= 5.5, < 5.10.240 >= 5.11, < 5.15.187 >= 5.16, < 6.1.144 >= 6.2, < 6.6.97 >= 6.7, < 6.12.37 >= 6.13, < 6.15.6 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 6.16 rc1 6.16 rc2 6.16 rc3 6.16 rc4 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Jul 25, 2025 | New CVE Received | kernel.org |