Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch linux linux_kernel systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
In the Linux kernel, the following vulnerability has been resolved:
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps
the next segment into ipv6_hdr->daddr, recompresses, then pulls the old
header and pushes the new one plus the IPv6 header back. The
recompressed header can be larger than the received one when the swap
reduces the common-prefix length the segments share with daddr (CmprI=0,
CmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes).
pskb_expand_head() was gated on segments_left == 0, so on earlier
segments the push consumed unchecked headroom. Once skb_push() leaves
fewer than skb->mac_len bytes in front of data,
skb_mac_header_rebuild()'s call to:
skb_set_mac_header(skb, -skb->mac_len);
will store (data - head) - mac_len into the u16 mac_header field, which
wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB
past skb->head.
A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two
segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one
pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.
Fix this by expanding the head whenever the remaining room is less than
the push size plus mac_len, and request that much extra so the rebuilt
MAC header fits afterwards.
CVE-2023-2156 was believed to be just a remote kernel DoS, patched in 2023.
We found a bypass and achieve privilege escalation and container escape.
Read the $10,500 story of CVE-2026-43501 "Route of Root":
https://nebusec.ai/research/cve-2026-43501-route-of-root/
Post summary
The post notes that CVE‑2023‑2156 was originally a remote kernel DoS, now patched, and reports a discovered bypass enabling privilege escalation and container escape. It also references a separate CVE‑2026‑43501 story.
LPE on any Linux distribution that has IPv6 and namespaces enabled (CVE-2023-2156) (@nebusecurity)
https://nebusec.ai/research/cve-2026-43501-route-of-root/
#infosec https://t.co/d9yQuvfSLQ
Post summary
The tweet discloses a local privilege escalation vulnerability in Linux systems with IPv6 and namespaces enabled, linking to research that likely provides further details.
A PoC/exploit has been discovered for vulnerability CVE-2026-43501
PT ID: PT-2026-42457
Vendor: Linux
Product: Linux
Description: An issue exists in the ipv6 rpl srh rcv() function during the decompression and recompression of RFC 6554 Source Routing Headers. When the recompressed header is larger than the received one, the process may consume unchecked headroom. If skb push() leaves fewer than skb->mac len bytes in front of the data, the skb set mac header() function called by skb mac header rebuild() can cause an integer wrap in the mac header field. This leads to a memory write operation that occurs approximately 64KiB past the skb->head buffer, resulting in an out-of-bounds write.
References:
• https://dbugs.ptsecurity.com/vulnerability/PT-2026-42457
• https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43501
#dbugs_vuln
Post summary
A PoC and exploit for CVE‑2026‑43501 have been discovered, accompanied by a detailed technical description and a GitHub repository containing the code.
#Analytics#Threat_Research
An analytical review of the main cybersecurity events (Sep 05-12, 2026)
1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack
// CVE-2026-15409
2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack
3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md
// Microsoft has failed to properly patch ShieldBreak CVE-2026-69414..
4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln
// CVE-2026-84388
5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1
// CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560, CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274
6⃣ Netscaler ADC Exploit
7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
8⃣ GRAYRABBIT One-click backdoor
// One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks
🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/
// An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org
Post summary
The post aggregates several recent CVEs, noting an instance of active exploitation for MikroTik RouterOS, but it lacks technical details, PoC references, or patch information.
Red hatはほぼバックポートしたカーネルのパッケージを補正しているので問題ないと思うが、念のためbugzillaに記載。
https://access.redhat.com/security/cve/cve-2026-43501
https://bugzilla.redhat.com/show_bug.cgi?id=2480457
Post summary
The post notes that Red Hat has largely backported a kernel patch for CVE‑2026‑43501, with no active exploitation or PoC mentioned.
Linux kernel bug CVE-2026-43501 was filed as denial-of-service only and patched back in 2023. Researchers found a bypass. One crafted IPv6 packet can still get you root on boxes with IPv6 and unprivileged namespaces enabled. They turned it into a $10,500 kernelCTF win.
https://nebusec.ai/research/cve-2026-43501-route-of-root/
Post summary
Researchers discovered a bypass of the CVE‑2026‑43501 patch, demonstrating privilege escalation via a crafted IPv6 packet; they provide a proof of concept, but no exploit code or evidence of active exploitation is mentioned.
@0xor0ne@nebusecurity Thanks for sharing!
It's actually two steps further from the 2023 CVE, since we also found a patch bypass: CVE-2026-43501.
So this is a writeup for both CVE-2023-2156 and CVE-2026-43501
Post summary
The tweet notes a writeup for CVE-2023-2156 and identifies a patch bypass for CVE-2026-43501, highlighting a workaround rather than exploit details.
Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs.
- An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled.
- The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100.
- The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available.
VULNERABILITY
CVE-2026-23274
CVE-2026-31659
CVE-2026-31678
CVE-2026-43042
CVE-2026-43074
CVE-2026-43501
CVE-2026-43502
CVE-2026-52912
CVE-2026-52923
CVE-2026-52924
CVE-2026-52929
CVE-2026-52933
CVE-2026-63834
CVE-2026-64560
CVE-2026-68162
CVE-2026-68376
CVE-2026-72137
CVE-2026-72255
CVE-2026-74480
CVE-2026-74581
CVE-2026-74597
CVE-2026-80714
Post summary
Researchers disclosed CVE-2026-43502 and other Linux kernel bugs, noting a local privilege-escalation flaw fixed by commit 44b550d88b26 in Linux v7.1-rc3, with no evidence of active exploitation or public PoC/Exploit details.
Route of Root: Bring a "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF | Nebula Security https://nebusec.ai/research/cve-2026-43501-route-of-root/
Post summary
Nebula Security’s write‑up presents a proof‑of‑concept for a DoS‑only kernel bug that can be exploited for local privilege escalation and bypasses an existing patch, illustrating how the CVE can be leveraged.
The tweet announces a firmware update that patches three CVEs for the Raritan IP‑PDU, signaling a patch release with no exploitation or PoC details mentioned.
CVE-2026-43501.
0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-43501
Post summary
A Proof of Concept has been discovered for CVE-2026-43501, but no additional details or evidence of active exploitation or mitigation steps are provided.
🚨 CVE-2026-43501: A PoC has been released for a Linux kernel vulnerability that can trigger an out-of-bounds memory write in the IPv6 networking stack under specific conditions.
🔗 https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43501
#CyberSecurity#CVE#Linux#ThreatWire
Post summary
A Proof of Concept for CVE‑2026‑43501, an out‑of‑bounds memory write in the Linux IPv6 stack, has been released and hosted on GitHub; no indications of active exploitation, patch status, or misinformation.
🐛 Linux IPv6 RPL out-of-bounds write (CVE-2026-43501) — not a Windows bug, but it still hits your WSL/Hyper-V/cloud bits. Memory-safety flaws don’t respect OS borders. Patch up. #Windows#Security#Linux#CVE
https://windowsforum.com/threads/cve-2026-43501-linux-ipv6-rpl-out-of-bounds-write-patch-the-right-kernels.419270/?utm_source=x&utm_medium=social&utm_campaign=news_node84
#LinuxKernel#WindowsInfrastructure https://t.co/eWHnOM0jvN
Post summary
The tweet alerts users to CVE-2026-43501, an out‑of‑bounds write in Linux IPv6 RPL that can affect WSL/Hyper‑V setups, and urges applying available patches, referencing a forum thread for more details.
CVE-2026-43501
In the Linux kernel, the following vulnerability has been resolved:
ipv6
https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43501
Post summary
The post announces that CVE‑2026‑43501 affecting the IPv6 stack in the Linux kernel has been addressed, though no further details or patch references are provided.