CVE-2026-43501Patch(linux / linux_kernel)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, then pulls the old header and pushes the new one plus the IPv6 header back. The recompressed header can be larger than the received one when the swap reduces the common-prefix length the segments share with daddr (CmprI=0, CmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes). pskb_expand_head() was gated on segments_left == 0, so on earlier segments the push consumed unchecked headroom. Once skb_push() leaves fewer than skb->mac_len bytes in front of data, skb_mac_header_rebuild()'s call to: skb_set_mac_header(skb, -skb->mac_len); will store (data - head) - mac_len into the u16 mac_header field, which wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB past skb->head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by expanding the head whenever the remaining room is less than the push size plus mac_len, and request that much extra so the rebuilt MAC header fits afterwards.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-131

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 13 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 8 signals
  • General: 3 classified signals
  • Peaked 11d ago at 2 mentions (2026-05-22); latest day: 1
  • 17 total mentions across 13 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline17 mentions / 13d
01122Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-24: 2Mentions · 2026-08-08: 1Mentions · 2026-08-18: 1Mentions · 2026-08-19: 2Mentions · 2026-08-21: 1Mentions · 2026-08-27: 2Mentions · 2026-08-31: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-24: 2PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-31: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-08-21: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-08-08: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-05-22: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-15: 105-2105-2207-0707-0807-2408-0808-1808-1908-2108-2708-3109-1209-15
Signal classification4 categories
Patch
635.3%
PoC
635.3%
General
317.6%
Disclosure
211.8%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-05-211
Patch1
2026-05-222
Disclosure1Patch1
2026-07-071
PoC1
2026-07-081
PoC1
2026-07-242
PoC2
2026-08-081
Patch1
2026-08-181
General1
2026-08-192
General1Patch1
2026-08-211
PoC1
2026-08-272
Disclosure1Patch1
2026-08-311
PoC1
2026-09-121
General1
2026-09-151
Patch1
Full discourse17 posts
  • Nebula Security@nebusecurity
    General

    CVE-2023-2156 was believed to be just a remote kernel DoS, patched in 2023. We found a bypass and achieve privilege escalation and container escape. Read the $10,500 story of CVE-2026-43501 "Route of Root": https://nebusec.ai/research/cve-2026-43501-route-of-root/

    Post summary

    The post notes that CVE‑2023‑2156 was originally a remote kernel DoS, now patched, and reports a discovered bypass enabling privilege escalation and container escape. It also references a separate CVE‑2026‑43501 story.

    5303147639.9K
    7.2K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    LPE on any Linux distribution that has IPv6 and namespaces enabled (CVE-2023-2156) (@nebusecurity) https://nebusec.ai/research/cve-2026-43501-route-of-root/ #infosec https://t.co/d9yQuvfSLQ

    Post summary

    The tweet discloses a local privilege escalation vulnerability in Linux systems with IPv6 and namespaces enabled, linking to research that likely provides further details.

    11511278010.8K
    94.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-43501 PT ID: PT-2026-42457 Vendor: Linux Product: Linux Description: An issue exists in the ipv6 rpl srh rcv() function during the decompression and recompression of RFC 6554 Source Routing Headers. When the recompressed header is larger than the received one, the process may consume unchecked headroom. If skb push() leaves fewer than skb->mac len bytes in front of the data, the skb set mac header() function called by skb mac header rebuild() can cause an integer wrap in the mac header field. This leads to a memory write operation that occurs approximately 64KiB past the skb->head buffer, resulting in an out-of-bounds write. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-42457 • https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43501 #dbugs_vuln

    Post summary

    A PoC and exploit for CVE‑2026‑43501 have been discovered, accompanied by a detailed technical description and a GitHub repository containing the code.

    011036125.6K
    3.4K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The post aggregates several recent CVEs, noting an instance of active exploitation for MikroTik RouterOS, but it lacks technical details, PoC references, or patch information.

    01052600
    3.4K followersView on X
  • OS開発者@hacker_infra
    Patch

    Red hatはほぼバックポートしたカーネルのパッケージを補正しているので問題ないと思うが、念のためbugzillaに記載。 https://access.redhat.com/security/cve/cve-2026-43501 https://bugzilla.redhat.com/show_bug.cgi?id=2480457

    Post summary

    The post notes that Red Hat has largely backported a kernel patch for CVE‑2026‑43501, with no active exploitation or PoC mentioned.

    02031567
    2.9K followersView on X
  • !Manan@0xManan
    PoC

    Linux kernel bug CVE-2026-43501 was filed as denial-of-service only and patched back in 2023. Researchers found a bypass. One crafted IPv6 packet can still get you root on boxes with IPv6 and unprivileged namespaces enabled. They turned it into a $10,500 kernelCTF win. https://nebusec.ai/research/cve-2026-43501-route-of-root/

    Post summary

    Researchers discovered a bypass of the CVE‑2026‑43501 patch, demonstrating privilege escalation via a crafted IPv6 packet; they provide a proof of concept, but no exploit code or evidence of active exploitation is mentioned.

    00030315
    2.2K followersView on X
  • Frank Wu@FrankOverF1ow
    Patch

    @0xor0ne @nebusecurity Thanks for sharing! It's actually two steps further from the 2023 CVE, since we also found a patch bypass: CVE-2026-43501. So this is a writeup for both CVE-2023-2156 and CVE-2026-43501

    Post summary

    The tweet notes a writeup for CVE-2023-2156 and identifies a patch bypass for CVE-2026-43501, highlighting a workaround rather than exploit details.

    00012360
    1.8K followersView on X
  • Brad Spengler@spendergrsec
    General

    Snippet is from: https://nebusec.ai/research/cve-2026-43501-route-of-root/

    Post summary

    The snippet provides minimal information, lacking details on exploitation, mitigation, or technical attributes of CVE‑2026‑43501.

    00030511
    7.1K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    Researchers disclosed CVE-2026-43502 and other Linux kernel bugs, noting a local privilege-escalation flaw fixed by commit 44b550d88b26 in Linux v7.1-rc3, with no evidence of active exploitation or public PoC/Exploit details.

    0002055
    98 followersView on X
  • -ENOMEM@masami256
    PoC

    Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF | Nebula Security https://nebusec.ai/research/cve-2026-43501-route-of-root/

    Post summary

    Nebula Security’s write‑up presents a proof‑of‑concept for a DoS‑only kernel bug that can be exploited for local privilege escalation and bypasses an existing patch, illustrating how the CVE can be leveraged.

    00001149
    2.4K followersView on X
  • しよ@udp_5060
    Patch

    RaritanのIP-PDU「PX3-5138JR」の最新ファームウェアがリリースされていたので適用(4.3.13.5-52458→4.3.14.5-52917)。 リリースノートにはCVE3件対応(CVE-2026-43501/CVE-2026-46037/CVE-2026-53275)とSCP実装修正との記載あり。 https://t.co/NXcW7gMqhu

    Post summary

    The tweet announces a firmware update that patches three CVEs for the Raritan IP‑PDU, signaling a patch release with no exploitation or PoC details mentioned.

    10000545
    1.2K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43501

    Post summary

    A Proof‑of‑Concept/exploit for CVE‑2026‑43501 has been discovered, but no details on the exploit code or active attacks are provided.

    1000056
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-43501. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43501

    Post summary

    A Proof of Concept has been discovered for CVE-2026-43501, but no additional details or evidence of active exploitation or mitigation steps are provided.

    1000073
    326 followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-43501: A PoC has been released for a Linux kernel vulnerability that can trigger an out-of-bounds memory write in the IPv6 networking stack under specific conditions. 🔗 https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43501 #CyberSecurity #CVE #Linux #ThreatWire

    Post summary

    A Proof of Concept for CVE‑2026‑43501, an out‑of‑bounds memory write in the Linux IPv6 stack, has been released and hosted on GitHub; no indications of active exploitation, patch status, or misinformation.

    0001075
    65 followersView on X
  • WindowsForum@windowsforum
    Patch

    🐛 Linux IPv6 RPL out-of-bounds write (CVE-2026-43501) — not a Windows bug, but it still hits your WSL/Hyper-V/cloud bits. Memory-safety flaws don’t respect OS borders. Patch up. #Windows #Security #Linux #CVE https://windowsforum.com/threads/cve-2026-43501-linux-ipv6-rpl-out-of-bounds-write-patch-the-right-kernels.419270/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #WindowsInfrastructure https://t.co/eWHnOM0jvN

    Post summary

    The tweet alerts users to CVE-2026-43501, an out‑of‑bounds write in Linux IPv6 RPL that can affect WSL/Hyper‑V setups, and urges applying available patches, referencing a forum thread for more details.

    0001059
    1.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Linux Kernel (CVE-2026-43501) https://vuldb.com/vuln/365008

    Post summary

    A new severe vulnerability in the Linux Kernel (CVE-2026-43501) has been disclosed, with a reference link to additional details on VulDB.

    0000068
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-43501 In the Linux kernel, the following vulnerability has been resolved: ipv6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43501

    Post summary

    The post announces that CVE‑2026‑43501 affecting the IPv6 stack in the Linux kernel has been addressed, though no further details or patch references are provided.

    0000067
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--

Explore more