CVE-2026-43456Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skbuff.c:2306! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306 RSP: 0018:ffffc90004aff760 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e RDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900 RBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000 R10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780 R13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0 Call Trace: <TASK> ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900 dev_hard_header include/linux/netdevice.h:3439 [inline] packet_snd net/packet/af_packet.c:3028 [inline] packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592 ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646 __sys_sendmsg+0x170/0x220 net/socket.c:2678 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe1a0e6c1a9 When a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond, bond_setup_by_slave() directly copies the slave's header_ops to the bond device: bond_dev->header_ops = slave_dev->header_ops; This causes a type confusion when dev_hard_header() is later called on the bond device. Functions like ipgre_header(), ip6gre_header(),all use netdev_priv(dev) to access their device-specific private data. When called with the bond device, netdev_priv() returns the bond's private data (struct bonding) instead of the expected type (e.g. struct ip_tunnel), leading to garbage values being read and kernel crashes. Fix this by introducing bond_header_ops with wrapper functions that delegate to the active slave's header_ops using the slave's own device. This ensures netdev_priv() in the slave's header functions always receives the correct device. The fix is placed in the bonding driver rather than individual device drivers, as the root cause is bond blindly inheriting header_ops from the slave without considering that these callbacks expect a specific netdev_priv() layout. The type confusion can be observed by adding a printk in ipgre_header() and running the following commands: ip link add dummy0 type dummy ip addr add 10.0.0.1/24 dev dummy0 ip link set dummy0 up ip link add gre1 type gre local 10.0.0.1 ip link add bond1 type bond mode active-backup ip link set gre1 master bond1 ip link set gre1 up ip link set bond1 up ip addr add fe80::1/64 dev bond1

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 41 mentions across 18 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 18 signals
  • Disclosure: 29 classified signals
  • General: 6 classified signals
  • Peaked 14d ago at 14 mentions (2026-07-03); latest day: 1
  • 41 total mentions across 18 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline41 mentions / 18d
0471114Mentions · 2026-05-08: 1Mentions · 2026-05-11: 1Mentions · 2026-05-15: 1Mentions · 2026-07-03: 14Mentions · 2026-07-04: 1Mentions · 2026-07-05: 3Mentions · 2026-07-06: 3Mentions · 2026-07-07: 5Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Mentions · 2026-07-29: 2Mentions · 2026-07-30: 1Mentions · 2026-08-02: 1Mentions · 2026-08-03: 2Mentions · 2026-08-06: 1Mentions · 2026-08-14: 1Mentions · 2026-08-16: 1Mentions · 2026-10-04: 1PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-07: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-07-03: 3Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-11: 1Technical Details · 2026-07-03: 4Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-07: 4Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-16: 105-0805-1105-1507-0307-0407-0507-0607-0707-0907-1007-2907-3008-0208-0308-0608-1408-1610-04
Signal classification3 categories
Disclosure
2972.5%
General
615.0%
Patch
512.5%
Referenced assets26 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-081
Patch1
2026-05-111
Patch1
2026-05-151
Disclosure1
2026-07-0314
Disclosure12General2
2026-07-041
Disclosure1
2026-07-053
Disclosure1General1Patch1
2026-07-063
Disclosure2Patch1
2026-07-075
Disclosure3General1Patch1
2026-07-091
Disclosure1
2026-07-101
Disclosure1
2026-07-292
Disclosure1General1
2026-07-301
Disclosure1
2026-08-021
Disclosure1
2026-08-032
Disclosure2
2026-08-061
Disclosure1
2026-08-141
Disclosure1
2026-08-161
General1
Full discourse20 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 rona (rqda_A) adlı bir güvenlik araştırmacısı, Linux kernel'de yaklaşık 19 yıldır bulunan bir 0-day güvenlik açığını paylaştı. CVE-2026-43456 olarak takip edilen bu açık, uygun koşullar sağlandığında 1 saniyeden kısa sürede yerel yetki yükseltme (Local Privilege Escalation) gerçekleştirilebilmesine olanak tanıyor. Bu açık bir RCE değil. Saldırganın hedef sistemde önceden kod çalıştırabiliyor ve CAP_NET_ADMIN yetkisine sahip olması gerekiyor. Bu şartlar sağlandığında ise root yetkisi elde edilebiliyor. Bu kernel açığı net/bonding modülünde type confusion (tip karışıklığı) hatası olarak geçiyor, etkilenen kernel sürümleri 2.6.24'ten başlayarak, düzeltmenin yayımlandığı sürümlere kadar (yaklaşık 6.12.77 ve öncesi) kapsıyor.

    Post summary

    A new Linux kernel local privilege escalation CVE (CVE‑2026‑43456) has been disclosed, detailing a type‑confusion flaw in the net/bonding module with an available patch covering kernels up to 6.12.77.

    32321228813.4K
    2.2K followersView on X
  • Brad Spengler@spendergrsec
    Patch

    Won 80k via kCTF, unpriv userns-reachable vuln: https://lore.kernel.org/linux-cve-announce/2026050859-CVE-2026-43456-ae60@gregkh/ We fixed in March, upstream 6.6 still unfixed 4 months later. https://t.co/omw78ssYtb

    Post summary

    The user announces that they fixed CVE‑2026‑43456 in March, notes it remains unfixed upstream, and links to the kernel mailing list announcement, but no PoC or exploit is shared.

    3110136538.5K
    7.1K followersView on X
  • yousukezan@yousukezan
    Disclosure

    19年以上見過ごされていたLinux kernelのゼロデイ脆弱性を報告した話:CVE-2026-43456 https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/

    Post summary

    A blog post announces a 19‑year‑old zero‑day vulnerability in the Linux kernel, identified as CVE‑2026‑43456.

    2200114399.2K
    14.9K followersView on X
  • Het Mehta@hetmehtaa
    Disclosure

    Last week in Linux: CVE-2026-43485: nouveau/gsp: drop WARN_ON in ACPI probes 2026-05-13 15:08 UTC CVE-2026-43484: mmc: core: Avoid bitfield RMW for claim/retune flags 2026-05-13 15:08 UTC CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated 2026-05-13 15:08 UTC CVE-2026-43482: sched_ext: Disable preemption between scx_claim_exit() and kicking helper work 2026-05-13 15:08 UTC CVE-2026-43481: net-shapers: don't free reply skb after genlmsg_reply() 2026-05-13 15:08 UTC CVE-2026-43480: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition 2026-05-13 15:08 UTC CVE-2026-43479: net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect 2026-05-13 15:08 UTC CVE-2026-43478: ASoC: codecs: rt1011: Use component to get the dapm context in spk_mode_put 2026-05-13 15:08 UTC CVE-2026-43489: liveupdate: luo_file: remember retrieve() status 2026-05-13 15:08 UTC CVE-2026-43488: usb: xhci: Prevent interrupt storm on host controller error (HCE) 2026-05-13 15:08 UTC CVE-2026-43487: ata: libata-core: Disable LPM on ST1000DM010-2EP102 2026-05-13 15:08 UTC CVE-2026-43486: arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults 2026-05-13 15:08 UTC CVE-2026-43476: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() 2026-05-13 15:08 UTC CVE-2026-43477: drm/i915/vrr: Configure VRR timings after enabling TRANS_DDI_FUNC_CTL 2026-05-13 15:08 UTC CVE-2026-43500: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present 2026-05-11 6:26 UTC CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads 2026-05-08 14:23 UTC CVE-2026-43461: spi: amlogic: spifc-a4: Fix DMA mapping error handling 2026-05-08 14:23 UTC CVE-2026-43460: spi: rockchip-sfc: Fix double-free in remove() callback 2026-05-08 14:23 UTC CVE-2026-43459: ASoC: soc-core: flush delayed work before removing DAIs and widgets 2026-05-08 14:23 UTC CVE-2026-43458: serial: caif: hold tty->link reference in ldisc_open and ser_release 2026-05-08 14:23 UTC CVE-2026-43457: mctp: i2c: fix skb memory leak in receive path 2026-05-08 14:23 UTC CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() 2026-05-08 14:23 UTC CVE-2026-43455: mctp: route: hold key->lock in mctp_flow_prepare_output() 2026-05-08 14:23 UTC CVE-2026-43475: scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT 2026-05-08 14:23 UTC CVE-2026-43474: fs: init flags_valid before calling vfs_fileattr_get 2026-05-08 14:23 UTC CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues 2026-05-08 14:23 UTC CVE-2026-43472: unshare: fix unshare_fs() handling 2026-05-08 14:23 UTC CVE-2026-43454: netfilter: nf_tables: Fix for duplicate device in netdev hooks 2026-05-08 14:23 UTC CVE-2026-43471: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() 2026-05-08 14:23 UTC CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir 2026-05-08 14:23 UTC CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths 2026-05-08 14:23 UTC CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq 2026-05-08 14:23 UTC CVE-2026-43467: net/mlx5: Fix crash when moving to switchdev mode 2026-05-08 14:23 UTC CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery 2026-05-08 14:23 UTC CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ 2026-05-08 14:23 UTC CVE-2026-43464: net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ 2026-05-08 14:23 UTC CVE-2026-43463: rxrpc, afs: Fix missing error pointer check after rxrpc_kernel_lookup_peer() 2026-05-08 14:23 UTC CVE-2026-43462: net: spacemit: Fix error handling in emac_tx_mem_map() 2026-05-08 14:23 UTC CVE-2026-43453: netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() 2026-05-08 14:23 UTC CVE-2026-43417: sched/mmcid: Handle vfork()/CLONE_VM correctly 2026-05-08 14:22 UTC CVE-2026-43426: usb: renesas_usbhs: fix use-after-free in ISR during device removal 2026-05-08 14:22 UTC CVE-2026-43425: usb: image: mdc800: kill download URB on timeout 2026-05-08 14:22 UTC CVE-2026-43424: usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling 2026-05-08 14:22 UTC CVE-2026-43423: usb: gadget: f_ncm: Fix atomic context locking issue 2026-05-08 14:22 UTC CVE-2026-43422: usb: legacy: ncm: Fix NPE in gncm_bind 2026-05-08 14:22 UTC CVE-2026-43421: usb: gadget: f_ncm: Fix net_device lifecycle with device_move 2026-05-08 14:22 UTC CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path 2026-05-08 14:23 UTC CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() 2026-05-08 14:22 UTC CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set 2026-05-08 14:22 UTC CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() 2026-05-08 14:22 UTC CVE-2026-43447: iavf: fix PTP use-after-free during reset 2026-05-08 14:22 UTC CVE-2026-43420: ceph: fix i_nlink underrun during async unlink 2026-05-08 14:22 UTC CVE-2026-43446: accel/amdxdna: Fix runtime suspend deadlock when there is pending job 2026-05-08 14:22 UTC CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup 2026-05-08 14:22 UTC CVE-2026-43444: drm/amdkfd: Unreserve bo if queue update failed 2026-05-08 14:22 UTC CVE-2026-43443: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition 2026-05-08 14:22 UTC CVE-2026-43442: io_uring: fix physical SQE bounds check for SQE_MIXED 128-byte ops 2026-05-08 14:22 UTC CVE-2026-43441: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled 2026-05-08 14:22 UTC CVE-2026-43440: net/mana: Null service_wq on setup error to prevent double destroy 2026-05-08 14:22 UTC CVE-2026-43439: cgroup: fix race between task migration and iteration 2026-05-08 14:22 UTC CVE-2026-43438: sched_ext: Remove redundant css_put() in scx_cgroup_init() 2026-05-08 14:22 UTC CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() 2026-05-08 14:22 UTC CVE-2026-43419: ceph: fix memory leaks in ceph_mdsc_build_path() 2026-05-08 14:22 UTC CVE-2026-43436: ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces 2026-05-08 14:22 UTC CVE-2026-43435: rust_binder: fix oneway spam detection 2026-05-08 14:22 UTC CVE-2026-43434: rust_binder: check ownership before using vma 2026-05-08 14:22 UTC CVE-2026-43433: rust_binder: avoid reading the written value in offsets array 2026-05-08 14:22 UTC CVE-2026-43432: usb: xhci: Fix memory leak in xhci_disable_slot() 2026-05-08 14:22 UTC CVE-2026-43431: xhci: Fix NULL pointer dereference when reading portli debugfs files 2026-05-08 14:22 UTC CVE-2026-43430: usb: yurex: fix race in probe 2026-05-08 14:22 UTC CVE-2026-43429: USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts 2026-05-08 14:22 UTC CVE-2026-43428: USB: core: Limit the length of unkillable synchronous timeouts 2026-05-08 14:22 UTC CVE-2026-43427: usb: class: cdc-wdm: fix reordering issue in read code path 2026-05-08 14:22 UTC CVE-2026-43418: sched/mmcid: Prevent CID stalls due to concurrent forks 2026-05-08 14:22 UTC CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time 2026-05-08 14:21 UTC CVE-2026-43392: sched_ext: Fix starvation of scx_enable() under fair-class saturation 2026-05-08 14:22 UTC CVE-2026-43391: nsfs: tighten permission checks for handle opening 2026-05-08 14:22 UTC CVE-2026-43390: nstree: tighten permission checks for listing 2026-05-08 14:21 UTC CVE-2026-43389: mm: memfd_luo: always dirty all folios 2026-05-08 14:21 UTC CVE-2026-43388: mm/damon/core: clear walk_control on inactive context in damos_walk() 2026-05-08 14:21 UTC CVE-2026-43387: staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() 2026-05-08 14:21 UTC CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain 2026-05-08 14:22 UTC CVE-2026-43415: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend 2026-05-08 14:22 UTC CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free 2026-05-08 14:22 UTC CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() 2026-05-08 14:22 UTC CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie 2026-05-08 14:21 UTC CVE-2026-43412: ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start 2026-05-08 14:22 UTC CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() 2026-05-08 14:22 UTC CVE-2026-43410: firmware: stratix10-rsu: Fix NULL pointer dereference when RSU is disabled 2026-05-08 14:22 UTC CVE-2026-43409: kprobes: avoid crash when rmmod/insmod after ftrace killed 2026-05-08 14:22 UTC CVE-2026-43408: ceph: add a bunch of missing ceph_path_info initializers 2026-05-08 14:22 UTC CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() 2026-05-08 14:22 UTC CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() 2026-05-08 14:22 UTC CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() 2026-05-08 14:22 UTC CVE-2026-43404: mm: Fix a hmm_range_fault() livelock / starvation problem 2026-05-08 14:22 UTC CVE-2026-43403: nsfs: tighten permission checks for ns iteration ioctls 2026-05-08 14:22 UTC CVE-2026-43385: net: Fix rcu_tasks stall in threaded busypoll 2026-05-08 14:21 UTC CVE-2026-43402: kthread: consolidate kthread exit paths to prevent use-after-free 2026-05-08 14:22 UTC CVE-2026-43401: cpufreq: intel_pstate: Fix NULL pointer dereference in update_cpu_qos_request() 2026-05-08 14:22 UTC CVE-2026-43400: drm/amdgpu: add upper bound check on user inputs in signal ioctl 2026-05-08 14:22 UTC CVE-2026-43399: drm/amdgpu/userq: Fix reference leak in amdgpu_userq_wait_ioctl 2026-05-08 14:22 UTC CVE-2026-43398: drm/amdgpu: add upper bound check on user inputs in wait ioctl 2026-05-08 14:22 UTC CVE-2026-43397: drm/bridge: samsung-dsim: Fix memory leak in error path 2026-05-08 14:22 UTC CVE-2026-43396: drm/xe/sync: Fix user fence leak on alloc failure 2026-05-08 14:22 UTC CVE-2026-43395: drm/xe/sync: Cleanup partially initialized sync on parse failure 2026-05-08 14:22 UTC CVE-2026-43394: nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() 2026-05-08 14:22 UTC CVE-2026-43393: btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() 2026-05-08 14:22 UTC CVE-2026-43384: net/tcp-ao: Fix MAC comparison to be constant-time 2026-05-08 14:21 UTC CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision 2026-05-08 14:21 UTC CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow 2026-05-08 14:21 UTC CVE-2026-43358: btrfs: add missing RCU unlock in error path in try_release_subpage_extent_buffer() 2026-05-08 14:21 UTC CVE-2026-43357: iio: gyro: mpu3050-core: fix pm_runtime error handling 2026-05-08 14:21 UTC CVE-2026-43356: iio: imu: adis: Fix NULL pointer dereference in adis_init 2026-05-08 14:21 UTC CVE-2026-43355: iio: light: bh1780: fix PM runtime leak on error path 2026-05-08 14:21 UTC CVE-2026-43382: batman-adv: Avoid double-rtnl_lock ELP metric worker 2026-05-08 14:21 UTC CVE-2026-43381: nouveau/dpcd: return EBUSY for aux xfer if the device is asleep 2026-05-08 14:21 UTC CVE-2026-43354: iio: proximity: hx9023s: Protect against division by zero in set_samp_freq 2026-05-08 14:21 UTC CVE-2026-43380: hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read 2026-05-08 14:21 UTC CVE-2026-43379: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() 2026-05-08 14:21 UTC CVE-2026-43378: smb: server: fix use-after-free in smb2_open() 2026-05-08 14:21 UTC CVE-2026-43377: ksmbd: Don't log keys in SMB3 signing and encryption key generation 2026-05-08 14:21 UTC CVE-2026-43376: ksmbd: fix use-after-free by using call_rcu() for oplock_info 2026-05-08 14:21 UTC CVE-2026-43375: net: mctp: fix device leak on probe failure 2026-05-08 14:21 UTC CVE-2026-43374: net: nexthop: fix percpu use-after-free in remove_nh_grp_entry 2026-05-08 14:21 UTC CVE-2026-43373: net: ncsi: fix skb leak in error paths 2026-05-08 14:21 UTC CVE-2026-43372: net: dsa: microchip: Fix error path in PTP IRQ setup 2026-05-08 14:21 UTC CVE-2026-43371: net: macb: Shuffle the tx ring before enabling tx 2026-05-08 14:21 UTC CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue 2026-05-08 14:21 UTC CVE-2026-43370: drm/amdgpu: Fix use-after-free race in VM acquire 2026-05-08 14:21 UTC CVE-2026-43369: drm/amd: Fix NULL pointer dereference in device cleanup 2026-05-08 14:21 UTC CVE-2026-43368: drm/i915: Fix potential overflow of shmem scatterlist length 2026-05-08 14:21 UTC CVE-2026-43367: drm/amd: Fix a few more NULL pointer dereference in device cleanup 2026-05-08 14:21 UTC CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle 2026-05-08 14:21 UTC CVE-2026-43365: xfs: fix undersized l_iclog_roundoff values 2026-05-08 14:21 UTC CVE-2026-43364: ublk: fix NULL pointer dereference in ublk_ctrl_set_size() 2026-05-08 14:21 UTC CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so 2026-05-08 14:21 UTC CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() 2026-05-08 14:21 UTC CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes 2026-05-08 14:21 UTC CVE-2026-43351: KVM: arm64: Eagerly init vgic dist/redist on vgic creation 2026-05-08 14:21 UTC CVE-2026-43352: i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue 2026-05-08 14:21 UTC CVE-2026-43350: smb: client: require a full NFS mode SID before reading mode bits 2026-05-08 13:41 UTC CVE-2026-43348: mshv_vtl: Fix vmemmap_shift exceeding MAX_FOLIO_ORDER 2026-05-08 13:41 UTC CVE-2026-43349: f2fs: fix to avoid uninit-value access in f2fs_sanity_check_node_footer 2026-05-08 13:41 UTC CVE-2026-43347: arm64: dts: qcom: monaco: Reserve full Gunyah metadata region 2026-05-08 13:39 UTC CVE-2026-43346: ice: ptp: don't WARN when controlling PF is unavailable 2026-05-08 13:39 UTC CVE-2026-43344: perf/x86/intel/uncore: Fix die ID init and look up bugs 2026-05-08 13:39 UTC CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ 2026-05-08 13:39 UTC CVE-2026-43343: usb: gadget: f_subset: Fix unbalanced refcnt in geth_free 2026-05-08 13:37 UTC CVE-2026-43342: usb: gadget: f_rndis: Protect RNDIS options with mutex 2026-05-08 13:37 UTC CVE-2026-43340: comedi: Reinit dev->spinlock between attachments to low-level drivers 2026-05-08 13:37 UTC CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill 2026-05-08 13:37 UTC CVE-2026-43321: bpf: Properly mark live registers for indirect jumps 2026-05-08 13:26 UTC CVE-2026-43320: drm/amd/display: Fix dsc eDP issue 2026-05-08 13:26 UTC CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock 2026-05-08 13:26 UTC CVE-2026-43318: drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify 2026-05-08 13:26 UTC CVE-2026-43317: most: core: fix leak on early registration failure 2026-05-08 13:26 UTC CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules 2026-05-08 13:26 UTC CVE-2026-43316: media: solo6x10: Check for out of bounds chip_id 2026-05-08 13:26 UTC CVE-2025-71300: Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" 2026-05-08 13:15 UTC CVE-2025-71301: drm/tests: shmem: Hold reservation lock around vmap/vunmap 2026-05-08 13:15 UTC CVE-2026-43314: dm: remove fake timeout to avoid leak request 2026-05-08 13:12 UTC CVE-2026-43315: KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3() succeeding 2026-05-08 13:12 UTC CVE-2026-43290: media: uvcvideo: Return queued buffers on start_streaming() failure 2026-05-08 13:11 UTC CVE-2026-43289: kexec: derive purgatory entry from symbol 2026-05-08 13:11 UTC CVE-2026-43288: ext4: move ext4_percpu_param_init() before ext4_mb_init() 2026-05-08 13:11 UTC CVE-2026-43287: drm: Account property blob allocations to memcg 2026-05-08 13:11 UTC CVE-2026-43286: mm/hugetlb: restore failed global reservations to subpool 2026-05-08 13:11 UTC CVE-2026-43285: mm/slab: do not access current->mems_allowed_seq if !allow_spin 2026-05-08 13:11 UTC CVE-2026-43313: ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4() 2026-05-08 13:12 UTC CVE-2026-43312: media: i2c: ov5647: Initialize subdev before controls 2026-05-08 13:12 UTC CVE-2026-43311: soc/tegra: pmc: Fix unsafe generic_handle_irq() call 2026-05-08 13:12 UTC CVE-2025-71299: spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing 2026-05-08 13:11 UTC CVE-2026-43310: media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC 2026-05-08 13:12 UTC CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid 2026-05-08 13:12 UTC CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() 2026-05-08 13:12 UTC CVE-2026-43307: iio: accel: adxl380: Avoid reading more entries than present in FIFO 2026-05-08 13:12 UTC CVE-2026-43306: bpf: crypto: Use the correct destructor kfunc type 2026-05-08 13:12 UTC CVE-2026-43305: drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path 2026-05-08 13:12 UTC CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN 2026-05-08 13:12 UTC CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() 2026-05-08 13:12 UTC CVE-2026-43302: drm/v3d: Set DMA segment size to avoid debug warnings 2026-05-08 13:12 UTC CVE-2026-43301: media: chips-media: wave5: Fix PM runtime usage count underflow 2026-05-08 13:12 UTC CVE-2025-71298: drm/tests: shmem: Hold reservation lock around madvise 2026-05-08 13:11 UTC CVE-2026-43300: drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove() 2026-05-08 13:12 UTC CVE-2026-43299: btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() 2026-05-08 13:12 UTC CVE-2026-43298: drm/amdgpu: Skip vcn poison irq release on VF 2026-05-08 13:12 UTC CVE-2026-43297: media: rockchip: rga: Fix possible ERR_PTR dereference in rga_buf_init() 2026-05-08 13:12 UTC CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky 2026-05-08 13:12 UTC CVE-2026-43295: rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net() 2026-05-08 13:12 UTC CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels 2026-05-08 13:11 UTC CVE-2026-43293: media: chips-media: wave5: Fix kthread worker destruction in polling mode 2026-05-08 13:11 UTC CVE-2026-43292: mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node 2026-05-08 13:11 UTC CVE-2026-43291: net: nfc: nci: Fix parameter validation for packet data 2026-05-08 13:11 UTC CVE-2025-71296: drm/tests: shmem: Hold reservation lock around purge 2026-05-08 13:11 UTC CVE-2025-71297: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() 2026-05-08 13:11 UTC CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags 2026-05-08 7:21 UTC CVE-2025-71285: net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels 2026-05-06 11:32 UTC CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs 2026-05-06 11:32 UTC CVE-2025-71293: drm/amdgpu/ras: Move ras data alloc before bad page check 2026-05-06 11:32 UTC CVE-2025-71292: jfs: nlink overflow in jfs_rename 2026-05-06 11:32 UTC

    Post summary

    The text provides a catalog of numerous CVE identifiers with brief kernel component notes, lacking evidence of PoC, exploitation, patches, or detailed vulnerability classification.

    3156704111.1K
    42.2K followersView on X
  • connect24h@connect24h
    Disclosure

    イエラエの中の人の記事。バグハンターは読んでおいたほうが良い。 CSIRT支援室 第37回 19年以上見過ごされていた Linux kernel のゼロデイ脆弱性を報告した話:CVE-2026-43456 https://scan.netsecurity.ne.jp/article/2026/07/30/55822.html

    Post summary

    The post references a newly reported zero‑day CVE-2026-43456 in the Linux kernel via a link, but provides no PoC, exploit, patch, technical detail, or evidence of active exploitation.

    012074404.1K
    7.5K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Disclosure

    19 year-old 0-day in Linux kernel, regular user to root CVE-2026-43456: Type confusion in the bonding driver (net/bonding) that slipped past everyone since 2007. It enables local privilege escalation to root for users with CAP_NET_ADMIN. KASLR leak & arbitrary code exec included. Watch the full chain from unprivileged shell to root below. Discovered via kernelCTF, patched in March 2026 https://x.com/rqda_A/status/2072948852483883033/video/1

    Post summary

    The tweet announces CVE-2026-43456, a type‑confusion flaw in the Linux kernel bonding driver that allows local privilege escalation, provides a demonstration video of the exploitation chain, and notes that a patch was released in March 2026.

    05054223.6K
    54.3K followersView on X
  • I'M H4CK3R 42@luckyhacker43

    [CVE-2026-43456] How a Linux kernel zero-day vulnerability went unnoticed for over 19 years before finally being reported 🤯🔥 👨‍💻 rona (x/rqda_A) 🔗 https://nvd.nist.gov/vuln/detail/cve-2026-43456 🔗 https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/ https://t.co/R2TtwySNN0

    06024111.4K
    5.0K followersView on X
  • ゆみや@stepney141
    Disclosure

    19年以上見過ごされていたLinux kernelのゼロデイ脆弱性を報告した話:CVE-2026-43456 https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/

    Post summary

    The post announces a 19‑year‑old zero‑day in the Linux kernel (CVE-2026-43456), but provides no further technical or exploitation details.

    0202262.1K
    1.6K followersView on X
  • ScanNetSecurity@ScanNetSecurity
    Disclosure

    Linuxカーネルに存在する脆弱性「CVE-2026-43456」をGMOイエラエが発見 https://scan.netsecurity.ne.jp/article/2026/08/03/55840.html?utm_source=twitter&utm_medium=social&utm_content=tweet

    Post summary

    A new Linux kernel vulnerability, CVE-2026-43456, was identified by GMO Yerae; the announcement provides no further details on PoC, exploitation, or mitigation.

    0101121.5K
    22.2K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Linuxカーネルに存在する脆弱性「CVE-2026-43456」をGMOイエラエが発見 | ScanNetSecurity https://s.netsecurity.ne.jp/article/2026/08/03/55840.html "根本原因となるコードは2007年に取り込まれて以降、約19年間にわたり修正されることなく存在しており、影響範囲はLinux 2.6.24から6.12.77までと広範囲に及ぶ"

    Post summary

    GMO YeraE has announced the discovery of CVE-2026-43456, a long‑standing kernel vulnerability that spans a broad range of Linux releases.

    10161620
    3.5K followersView on X
  • The CyberSec Guru@thecybersecguru
    Patch

    🚨 A 19-year-old Linux kernel bug silently survived in production before finally being uncovered. CVE-2026-43456 isn't just another privilege escalation bug. It combines: 🔹 Type Confusion 🔹 GRE Tunnels 🔹 Linux Bonding 🔹 329 Chained Network Interfaces 🔹 SKB Metadata Corruption 🔹 KASLR Bypass The result? ⚠️ 99%+ reliable local privilege escalation in under 1 second. I wrote a deep technical breakdown covering: ✅ Why the bug stayed hidden since 2007 ✅ The exact root cause in the bonding driver ✅ How attackers leak kernel addresses ✅ Why 329 interfaces is the magic number ✅ How the exploit achieves code execution ✅ Mitigations and patched kernel versions 📖 Full article: https://thecybersecguru.com/exploits/cve-2026-43456-linux-kernel-zero-day/ 🔁 Repost if you think this is one of the most fascinating Linux kernel vulnerabilities discovered this year.

    Post summary

    The post announces a new Linux kernel privilege‑escalation CVE with detailed technical explanation and mentions mitigation steps and patched kernel versions, but provides no PoC, exploit code, or evidence of active exploitation.

    02052481
    1.5K followersView on X
  • 小池悠生@shojin_comp
    General

    CVE-2026-43456、一応修正入ってないディストリビューションもちらほらあるみたいなのでお気をつけを https://explore.alas.aws.amazon.com/CVE-2026-43456.html

    Post summary

    The post alerts that CVE‑2026‑43456 remains unpatched in some distributions and points to a URL for additional information.

    01070908
    1.4K followersView on X
  • PonPoko Tanuki@TnukiPonpoko
    Disclosure

    https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/ 19年以上見過ごされていた Linux kernelのゼロデイ脆弱性を報告した話: CVE-2026-43456

    Post summary

    The blog post announces the identification of a long‑overlooked Linux kernel zero‑day vulnerability (CVE‑2026‑43456) without providing supporting PoC, exploitation, or mitigation details.

    0004091
    1.2K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    19年以上見過ごされていたLinux kernelのゼロデイ脆弱性を報告した話:CVE-2026-43456 | セキュリティブログ |GMOサイバーセキュリティ byイエラエ https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/ "Bondingと呼ばれるネットワーク機能に存在する脆弱性のため、この機能を無効にすると影響はありません"

    Post summary

    The blog announces the discovery of a long‑overlooked Linux kernel zero‑day (CVE‑2026‑43456) and notes that disabling the Bonding networking feature serves as a mitigation, but no exploit code or evidence of active attacks is presented.

    01021416
    3.5K followersView on X
  • ScanNetSecurity@ScanNetSecurity
    General

    CSIRT支援室 第37回 19年以上見過ごされていた Linux kernel のゼロデイ脆弱性を報告した話:CVE-2026-43456 https://scan.netsecurity.ne.jp/article/2026/07/30/55822.html?utm_source=twitter&utm_medium=social&utm_content=tweet

    Post summary

    The text announces a previously overlooked zero‑day vulnerability in the Linux kernel (CVE‑2026‑43456) but provides no additional details about proof of concept, exploitation, patching, or active use.

    000201.1K
    22.0K followersView on X
  • ASPL hosting@ASPLhosting
    Disclosure

    🚨 CVE-2026-43456 "GRE-Bond Confusion": un fallo del kernel Linux presente 19 años (2007-2026) que permite a un usuario sin privilegios hacerse root. Incluso escapar de un contenedor (Docker/LXC/Proxmox) hasta root del host. Casi todas las distros afectadas. Te lo explicamos 👇

    Post summary

    CVE-2026-43456 is a long-standing Linux kernel vulnerability enabling unprivileged users to gain root and escape containers to host root, impacting nearly all Linux distributions.

    1000175
    129 followersView on X
  • Cyber Kendra@cyberkendra
    Disclosure

    A single line of code from 2007 just earned two researchers $80k+. CVE-2026-43456: a type confusion bug hidden in Linux's bonding driver for 19 years. Full root access in under 1 second, 99%+ success rate. Affects kernels 2.6.24 → 6.12.77 https://www.cyberkendra.com/2026/07/19-year-old-linux-kernel-bug-earns-80k.html #Linux #Security https://t.co/ZcxK83xEFg

    Post summary

    The post announces the discovery of a 19‑year‑old type‑confusion bug in Linux’s bonding driver, highlighting its severity and potential for rapid root takeover, while linking to a detailed news article.

    00020150
    1.5K followersView on X
  • Masayuki Hatta@mhatta
    General

    19年以上見過ごされていたLinux kernelのゼロデイ脆弱性を報告した話:CVE-2026-43456 | セキュリティブログ | 脆弱性診断(セキュリティ診断)のGMOサイバーセキュリティ byイエラエ https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/

    Post summary

    The article announces a 19‑year‑old Linux kernel zero‑day CVE but provides no further details on exploitation, patches, or technical specifics.

    00002317
    6.4K followersView on X
  • Toshiya SAITOH@stoshiya
    Disclosure

    19年以上見過ごされていたLinux kernelのゼロデイ脆弱性を報告した話:CVE-2026-43456 https://gmo-cybersecurity.com/blog/19-year-old-linux-kernel-zero-day/

    Post summary

    A blog post announces the newly disclosed CVE-2026-43456, a Linux kernel zero-day that has reportedly existed for over 19 years.

    00002181
    1.1K followersView on X
  • satera@satera01
    Disclosure

    19年以上見過ごされていたLinux kernelのゼロデイ脆弱性を報告した話:CVE-2026-43456 | セキュリティブログ | 脆弱性診断(セキュリティ診断)のGMOサイバーセキュリティ byイエラエ https://share.google/izDOdFW1s68vOGIKf

    Post summary

    The blog post announces the disclosure of a long‑overlooked Linux kernel zero‑day vulnerability (CVE‑2026‑43456) but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    10010182
    205 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more