CVE-2026-43494Disclosure(linux / linux_kernel)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user().

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1341

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-22); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-05-21: 2Mentions · 2026-05-22: 4Mentions · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-25: 1Exploit Tool / Code · 2026-05-25: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-22: 2Technical Details · 2026-05-22: 2Technical Details · 2026-05-25: 105-2105-2205-25
Signal classification4 categories
Disclosure
228.6%
Patch
228.6%
General
228.6%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-212
Disclosure1Patch1
2026-05-224
Disclosure1General2Patch1
2026-05-251
PoC1
Full discourse7 posts
  • hsn今天吃什么@hsn8086k
    General

    Linux 重置密码大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300) -PinTheft (CVE-2026-43494)

    Post summary

    The entry lists several Linux password‑reset CVEs without details on PoC, exploitation, patches, or technical specifics.

    43118972036546.3K
    2.3K followersView on X
  • 321sweet~❤️(Ictye)@IctyeP
    Disclosure

    Linux新的漏洞:CVE-2026-43494 /PinTheft利用io_uring都设计缺陷实现引用计数窃取导致缓存被错误释放然后再读取特定文件获取修改页缓存的权限进而实现攻击 目前这和漏洞的话影响范围比较有限,只有加载较新的io_uring的才会受影响(目前已有合并的修复补丁),目前确认的有arch和Fedora

    Post summary

    A new Linux kernel flaw (CVE‑2026‑43494) affects io_uring by leaking reference counts and corrupting cache, and a patch has already been merged; the exploit is named "PinTheft" but no active attacks are reported.

    00030289
    1.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-43494 In the Linux kernel, the following vulnerability has been resolved: net/rds https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43494

    Post summary

    CVE‑2026‑43494 in the Linux kernel has been fixed; the issue in the net/rds module has been resolved, indicating that a patch or fix is already in place.

    01010116
    4.0K followersView on X
  • Brad Spengler@spendergrsec
    Disclosure

    Has a CVE today: https://lore.kernel.org/linux-cve-announce/2026052130-CVE-2026-43494-a65a@gregkh/T/#u

    Post summary

    A new CVE (CVE-2026-43494) was announced via a link, with no Proof of Concept, exploit details, or patch information provided.

    00020391
    7.0K followersView on X
  • dbugs@ptdbugs
    PoC

    PinTheft: reset op_nents when zerocopy page pin fails CVE: CVE-2026-43494 PT ID: PT-2026-42451 Vendor: Linux Product: Linux CVSS: n/a Credits: n/a Description: In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user(). References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-43494 • https://git.kernel.org/stable/c/9115669faedccdda100428e2d26fd0aac8c50799 Poc/Exploit: https://github.com/jayhutajulu1/CVE-2026-43494-PinTheft-PoC #dbugs_vuln

    Post summary

    A PoC and exploit script for CVE-2026-43494 were released, which fixes an op_nents reset bug in the Linux kernel's RDS module. The vulnerability has been patched and no evidence of active exploitation is provided.

    00001231
    1.2K followersView on X
  • Luis Lescano@luadoles
    General

    - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300) -PinTheft (CVE-2026-43494)

    Post summary

    The text lists several CVE identifiers and associated codenames without any supporting detail, claim, or context.

    10000294
    31 followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 Linux RDS double-free (CVE-2026-43494) is the reminder that “rare error path” = attacker’s favorite shortcut. Stale pin/accounting → boom. Fixes matter even if you never touch RDS. #WindowsForum #Security #Linux https://windowsforum.com/threads/cve-2026-43494-linux-rds-double-free-pintheft-lpe-risk-and-mitigations.419282/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LocalPrivilegeEscalation https://t.co/kfUlFqTOGv

    Post summary

    The post highlights CVE‑2026‑43494 as a double‑free flaw in Linux RDS, notes that fixes are critical, and points to a thread discussing mitigations, but provides no exploit or PoC details.

    0000177
    1.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more