CVE-2026-43039Disclosure(linux / linux_kernel)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wrong recycle in ZC RX dispatch emac_dispatch_skb_zc() allocates a new skb via napi_alloc_skb() but never copies the packet data from the XDP buffer into it. The skb is passed up the stack containing uninitialized heap memory instead of the actual received packet, leaking kernel heap contents to userspace. Copy the received packet data from the XDP buffer into the skb using skb_copy_to_linear_data(). Additionally, remove the skb_mark_for_recycle() call since the skb is backed by the NAPI page frag allocator, not page_pool. Marking a non-page_pool skb for recycle causes the free path to return pages to a page_pool that does not own them, corrupting page_pool state. The non-ZC path (emac_rx_packet) does not have these issues because it uses napi_build_skb() to wrap the existing page_pool page directly, requiring no copy, and correctly marks for recycle since the page comes from page_pool_dev_alloc_pages().

4.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 6 mentions (2026-05-12); latest day: 4
  • 10 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 2d
02356Mentions · 2026-05-12: 6Mentions · 2026-05-13: 4Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-12: 6Technical Details · 2026-05-13: 305-1205-13
Signal classification4 categories
Disclosure
660.0%
Patch
220.0%
Active Exploitation
110.0%
General
110.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-126
Active Exploitation1Disclosure4Patch1
2026-05-134
Disclosure2General1Patch1
Full discourse10 posts
  • Wazuh@wazuh
    Patch

    The Linux kernel is affected by CVE-2026-43039 (CVSS 9.8), a critical information disclosure flaw in the “ti: icssg-prueth” driver that exposes kernel heap memory to userspace. Affects versions prior to 6.19.12. Update to 6.19.12 or later. Read more: https://ow.ly/hRKq50YYbai https://t.co/buDFeRIHk2

    Post summary

    The note reports the CVE‑2026‑43039 kernel driver information disclosure flaw and recommends updating to Linux kernel 6.19.12 or newer.

    01111961.7K
    8.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE: CVE-2026-43039 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wrong recycle in ZC RX…

    Post summary

    CVE‑2026‑43039 is a critical Linux kernel flaw that has already been patched; the text gives CVSS and fix details but no PoC, exploit, or active exploitation claims.

    1000039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Copy the received packet data from the XDP buffer into the skb using skbcopytolineardata(). CVE: CVE-2026-43039 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces CVE-2026-43039, providing its CVSS score and critical severity, but gives no Proof of Concept, exploit code, or mitigation details.

    1000032
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-43039 (CVSS 9.8) — multiple products. CVE: CVE-2026-43039 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-43039 as a critical vulnerability with a CVSS score of 9.8, but provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    1000032
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    13:19 UTC: Thread live on @lyrie_ai. 0day Intel: The Linux kernel is affected by CVE-2026-43039 (CVSS 9.8), a critical informatio

    Post summary

    The post announces the discovery of CVE‑2026‑43039, a critical Linux kernel vulnerability with a CVSS score of 9.8, but provides no proof of concept, exploit, or mitigation details.

    1000045
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    16:05 UTC: First exploit attempt in the wild. 0day Intel: The Linux kernel is affected by CVE-2026-43039 (CVSS 9.8), a critical informatio

    Post summary

    The text announces the first in-the-wild exploit attempt against CVE-2026-43039, a critical Linux kernel vulnerability, without providing PoC details or a patch.

    1000069
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    13:08 UTC: Lyrie Sentinel flagged it. 0day Intel: The Linux kernel is affected by CVE-2026-43039 (CVSS 9.8), a critical informatio

    Post summary

    A new critical vulnerability, CVE-2026-43039, has been identified in the Linux kernel with a CVSS score of 9.8.

    1000042
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    13:05 UTC: CVE-2026-43039 disclosed. The Linux kernel is affected by CVE-2026-43039 (CVSS 9.8), a critical information disclosure flaw in the “ti: icssg-prue

    Post summary

    CVE-2026-43039 has been disclosed; it is a critical information disclosure vulnerability in the Linux kernel with a CVSS score of 9.8.

    1000051
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    13:16 UTC: GPT-5 enrichment complete. 72 words. 1 citations. 0day Intel: The Linux kernel is affected by CVE-2026-43039 (CVSS 9.8), a critical informatio

    Post summary

    A brief disclosure announcing a new critical Linux kernel vulnerability (CVE‑2026‑43039) with a CVSS score of 9.8, but lacking further technical, exploitation, or mitigation details.

    1000048
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43039-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet links to a CVE advisory but provides no substantive information on exploitation, patches, or detailed vulnerability characteristics.

    0000025
    210 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more