CVE-2026-43502Patch(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. However, zerocopy ownership is really determined by the presence of op_mmp_znotifier, regardless of whether the message has reached the socket queue. Capture op_mmp_znotifier up front in rds_message_purge() and use it as the cleanup discriminator. If the message is already associated with a socket, keep the existing completion path. Otherwise, drop the pinned page accounting directly and release the notifier before putting the payload pages. This keeps early send failure cleanup consistent with the zerocopy lifetime rules without changing the normal queued completion path.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 22 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 15 signals
  • General: 5 classified signals
  • Peaked 7d ago at 5 mentions (2026-09-08); latest day: 1
  • 22 total mentions across 11 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline22 mentions / 11d
01345Mentions · 2026-05-21: 1Mentions · 2026-09-05: 2Mentions · 2026-09-06: 2Mentions · 2026-09-08: 5Mentions · 2026-09-10: 2Mentions · 2026-09-12: 1Mentions · 2026-09-14: 4Mentions · 2026-09-15: 2Mentions · 2026-09-20: 1Mentions · 2026-09-23: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-09-05: 2PoC Mentioned / Linked · 2026-09-08: 3PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-09-05: 2Exploit Tool / Code · 2026-09-08: 2Exploit Tool / Code · 2026-09-15: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-09-05: 2Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-10: 1Patch / Workaround · 2026-09-14: 2Patch / Workaround · 2026-09-15: 2Patch / Workaround · 2026-09-20: 1Patch / Workaround · 2026-09-24: 1Technical Details · 2026-09-05: 2Technical Details · 2026-09-06: 2Technical Details · 2026-09-08: 3Technical Details · 2026-09-10: 1Technical Details · 2026-09-14: 4Technical Details · 2026-09-15: 1Technical Details · 2026-09-20: 1Technical Details · 2026-09-24: 105-2109-0509-0609-0809-1009-1209-1409-1509-2009-2309-24
Signal classification5 categories
Patch
836.4%
General
522.7%
PoC
418.2%
Disclosure
418.2%
Exploit
14.5%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-211
Patch1
2026-09-052
Exploit1PoC1
2026-09-062
General2
2026-09-085
Disclosure1General1PoC3
2026-09-102
General1Patch1
2026-09-121
General1
2026-09-144
Disclosure2Patch2
2026-09-152
Patch2
2026-09-201
Patch1
2026-09-231
Disclosure1
2026-09-241
Patch1
Full discourse20 posts
  • Cyber Meowfia@cybermeowfia
    Exploit

    Today's exploit, ZcopyReaper is for openSUSE, a lifecycle vulnerability in net/rds: CVE-2026-43502. ZcopyReaper was introduced in Feb 2018 and fixed upstream in May 2026. Discovered and exploited by the NebuSec security pipeline. EXP source: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43502-openSUSE-6.4.0-150600 https://t.co/ax7hZHzvSv

    Post summary

    The message announces a functional exploit (ZcopyReaper) for CVE‑2026‑43502 on openSUSE, links to source code, notes exploitation by NebuSec’s pipeline, and indicates the issue was fixed upstream, but does not report wild exploitation.

    123295307.3K
    439 followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    ZcopyReaper : nueva vulnerabilidad de Linux permite escalada de privilegios Se ha descubierto una nueva vulnerabilidad en el kernel de Linux llamada ZcopyReaper (identificada como CVE-2026-43502) https://blog.elhacker.net/2026/09/zcopyreaper-nueva-vulnerabilidad-de.html

    Post summary

    The text reports the discovery of CVE-2026-43502, a Linux kernel privilege escalation vulnerability, without mentioning any PoC, exploit, active exploitation, or patch.

    010038194.5K
    142.4K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 HIGH: Public PoC code has been released for ZcopyReaper (CVE-2026-43502), a Linux kernel local privilege escalation vulnerability in the RDS zerocopy send path. The flaw allows an unprivileged local user to escalate privileges when the affected RDS functionality is available, potentially leading to full system compromise. ⚠️ The vulnerability was introduced in Linux 4.17 and has been fixed upstream. Public exploitation code now increases the risk for affected systems. 🔴 Update to a patched kernel and ensure the RDS functionality is not unnecessarily exposed. 🔗 http://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43502-openSUSE-6.4.0-150600 #Linux #LinuxKernel #CVE #LPE #ZcopyReaper #CyberSecurity #Infosec

    Post summary

    A public PoC code for CVE‑2026‑43502, a Linux kernel LPE via RDS zerocopy, has been released; a patch is available and risk is heightened by the publicly available exploit.

    0201472.1K
    1.7K followersView on X
  • Hack32@Hack32_
    PoC

    Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) 💀☠️ https://securityonline.info/zcopyreaper-linux-vulnerability/?utm_source=twitter&utm_medium=social_share

    Post summary

    The text announces that a publicly available proof‑of‑concept for the Linux vulnerability CVE‑2026‑43502 has been released, linking to a site likely containing the PoC details.

    0101651.3K
    828 followersView on X
  • bearstech@bearstech
    Patch

    ZcopyReaper (CVE-2026-43502) nous avons déployé cette nuit les mesures de contournement. Toutes nos VM ont été redémarrées en moins d’une heure. 👉 En savoir plus sur nos offres d'infogérance : https://bearstech.com/contact Merci à @OctopuceFR et @evolix pour votre collaboration sur ce sujet.

    Post summary

    The post announces that mitigation measures for CVE‑2026‑43502 have been deployed, with all VMs rebooted in under an hour, highlighting a workaround rather than an exploit.

    1401151.2K
    18.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 NebuSec, Linux Kernel'deki CVE-2026-43502 için ZcopyReaper PoC'si yayınladı. Açık, kernel'in net/rds bileşenindeki zerocopy send cleanup işleminden kaynaklanıyor. 🔴 CVSS: 7.8 🔴 Yerel, düşük yetkili kullanıcı tarafından tetiklenebiliyor 🔴 Kernel seviyesinde bellek bozulması / yetki yükseltme riski 🔴 PoC, openSUSE/SUSE 6.4.0-150600 kernel üzerinde yayınlandı 🔴 Linux upstream düzeltmesi Mayıs 2026'da yayınlandı Poc/Exploit: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43502-openSUSE-6.4.0-150600 https://x.com/cybermeowfia/status/2096092497684668471/video/1

    Post summary

    NebuSec released a PoC for CVE‑2026‑43502, demonstrating a kernel‑level memory corruption/privilege escalation achievable by a local low‑privileged user, and notes an upstream patch scheduled for May 2026.

    02061464
    2.4K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The post summarizes recent CVEs with references to active exploitation, but lacks deep technical or patch details, making it a high‑level roundup.

    01052600
    3.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Linux カーネルの脆弱性 ZcopyReaper CVE-2026-43502 が FIX:root 権限昇格の恐れ https://iototsecnews.jp/2026/09/14/new-zcopyreaper-linux-kernel-vulnerability-enables-privilege-escalation-attacks/ Linux カーネルの RDS サブシステムにおける Zero-Copy 送信の失敗処理に不備があり、CVE-2026-43502 として識別される深刻な問題が存在します。ソケットへ未関連付けの段階で発生する不適切なメモリ解放が原因であり、カーネルメモリの破壊を引き起こします。低権限ユーザーによる root 権限奪取が可能となり、ユーザーネームスペース制限の無効化/任意コード実行/システム制御権限の喪失といった深刻な影響が生じます。対応策として、修正パッチの適用/カーネル再起動による更新/不要な RDS モジュールのブラックリスト化/ロード無効化が求められます。 #CVE202643502 #Kernel #Linux #Vulnerability #ZcopyReaper

    Post summary

    The post discloses a Linux kernel zero‑copy RDS vulnerability (CVE-2026-43502) that allows privilege escalation and recommends applying a fix patch, rebooting the kernel, and blacklisting/disabling the RDS module as mitigation.

    03021230
    519 followersView on X
  • Brad Spengler@spendergrsec
    General

    For oss-sec: CVE-2026-72137 needs xfrm, CVE-2026-52933 needs io_uring, CVE-2026-52929 needs sctp, CVE-2026-43502 needs rds (is what the original post was about)

    Post summary

    The post enumerates several CVE identifiers and the subsystems they target but offers no additional technical, exploit, or remediation information.

    00042767
    7.1K followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Patch

    NebuSec reveló la vulnerabilidad CVE-2026-43502 (ZcopyReaper), una falla en el subsistema RDS del kernel de Linux presente desde la versión 4.17. El fallo en la limpieza de memoria zero-copy permite a usuarios locales sin privilegios corromper la memoria del núcleo y obtener acceso total como root, evadiendo las restricciones tradicionales de espacio de nombres (user namespaces). Los parches de seguridad ya fueron publicados en el código principal de Linux y distribuidos a sistemas como Ubuntu y Debian.

    Post summary

    The tweet discloses CVE-2026-43502 (ZcopyReaper), a zero-copy memory cleanup vulnerability in the Linux RDS subsystem enabling local privilege escalation to root, and notes that security patches have been released in mainline Linux and distributed to Ubuntu and Debian.

    01021334
    3.8K followersView on X
  • -ENOMEM@masami256
    Disclosure

    oss-security - Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more https://www.openwall.com/lists/oss-security/2026/09/08/1

    Post summary

    A brief announcement on the oss‑security mailing list lists the CVE‑2026‑43502 local privilege escalation in Linux kernel along with 20 additional similar issues, but it provides no proof‑of‑concept, exploit code, or mitigation details.

    12010289
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    The details and PoC exploit code for the ZcopyReaper Linux vulnerability (CVE-2026-43502) are publicly disclosed, posing a privilege escalation risk. #ZcopyReaper #CVE202643502 #LinuxKernel #CyberSecurity #PrivilegeEscalation https://securityonline.info/zcopyreaper-linux-vulnerability/ https://t.co/SdlOKuad1N

    Post summary

    Information on CVE-2026-43502, a ZcopyReaper Linux kernel privilege‑escalation vulnerability, has been publicly disclosed along with PoC exploit code, but no evidence of active exploitation or patches is provided.

    00012472
    12.9K followersView on X
  • LinuxSecurity@lnxsec
    Patch

    Kernel version numbers are a poor shortcut for deciding whether a distribution is vulnerable. The upstream fix for CVE-2026-43502 landed in a newer mainline kernel, but stable trees and distributions can backport the fix without adopting that version number. That distinction matters in Linux environments where vulnerability scanners, CMDB data, and human triage all see different representations of the same host. A system can look old and be fixed, or look current and still be running an unpatched package after a reboot was missed. **In practical terms, it is a good time to:** - record both the installed kernel package and the kernel currently returned by `uname -r` - compare scanner findings with the distribution's CVE and package advisory status - verify whether updated kernel packages have actually been booted on long-lived systems - check package history for failed or deferred kernel updates The useful takeaway is simple: distribution backport status belongs in vulnerability triage, not as an afterthought. #VulnerabilityManagement #PatchManagement #LinuxSecurity #SysAdmin https://linuxsecurity.com/features/linux-privilege-escalation-rds-cleanup-bug

    Post summary

    The text emphasizes patch and backport status for CVE-2026-43502, recommending verification of installed kernel packages, advisories, and booted updates. It does not mention PoC, exploit code, active exploitation, or technical vulnerability details.

    0002090
    4.5K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    Researchers disclosed 21 Linux kernel vulnerabilities, highlighted by CVE-2026-43502 (RDS zerocopy LPE), providing technical details, affected versions, and noting the fix in commit 44b550d88b26 (Linux v7.1-rc3) alongside the availability of public exploits.

    0002055
    98 followersView on X
  • Windows Forum@windowsforum
    Patch

    🐧 ZcopyReaper sounds apocalyptic, but CVE-2026-43502 needs local access and RDS enabled. Patch it anyway—Linux security is safest when “probably not exposed” isn’t the plan. https://windowsforum.com/news/cve-2026-43502-linux-root-flaw-requires-rds-has-fixes.445128/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #PrivilegeEscalation #KernelVulnerability #LinuxSecurity #RdsNetworking https://t.co/3OYJjY28DC

    Post summary

    The tweet discusses CVE-2026-43502, noting it requires local access and RDS, and explicitly advises patching despite the scary name 'ZcopyReaper'.

    1000049
    1.4K followersView on X
  • LinuxSecurity@lnxsec
    General

    A kernel hardening control can be working exactly as designed and still be irrelevant to the exploit path in front of you. CVE-2026-43502 is a useful example. The demonstrated RDS privilege-escalation path does not require user namespaces or Linux capabilities. That matters because teams often treat disabling unprivileged user namespaces as a broad answer to local kernel exploitation. It is not. The more important question is whether the vulnerable RDS path is reachable on the running system: is RDS built in, loaded, or available for autoloading, and does the installed kernel package actually carry the fix? **In practical terms, it is a good time to:** - inspect the running kernel configuration for `CONFIG_RDS`, `CONFIG_RDS_TCP`, `CONFIG_INET`, and `CONFIG_AIO` - run `lsmod` and verify whether `rds` or `rds_tcp` are already loaded - check module alias and autoload behavior to determine whether RDS can be pulled in on demand - confirm the distribution's package status for CVE-2026-43502 rather than inferring exposure from the upstream version alone How often do your hardening reviews test whether a control blocks the actual exploit prerequisites rather than simply confirming that the control is enabled? #LinuxSecurity #KernelSecurity #VulnerabilityManagement #LinuxHardening https://linuxsecurity.com/features/linux-privilege-escalation-rds-cleanup-bug

    Post summary

    The post provides technical details about CVE-2026-43502’s RDS privilege escalation path and advises on verification steps, but it does not offer a PoC, active exploitation evidence, or patch information.

    0000197
    4.5K followersView on X
  • LinuxSecurity@lnxsec
    Disclosure

    The difference between 'installed' and 'running' is where kernel patch programs quietly fail. A fixed package on disk does not protect a host that is still booted into the vulnerable kernel. For CVE-2026-43502, package status and runtime state both matter. **In practical terms, it is a good time to:** - compare `uname -r` with the newest installed kernel package - identify hosts with pending reboot requirements after kernel updates - verify the distribution advisory status for CVE-2026-43502 #PatchManagement #LinuxSecurity #SysAdmin https://linuxsecurity.com/features/linux-privilege-escalation-rds-cleanup-bug

    Post summary

    The text announces CVE-2026-43502 and advises sysadmins to check kernel version vs. installed packages and reboot status, but provides no named patch, PoC, exploit, or active-exploitation evidence.

    0000083
    4.5K followersView on X
  • Nullvy CyberNews@ncnarabic
    Disclosure

    كشف باحثو "نيبوسيك" عن ثغرة في نواة "لينكس" أسموها "زي كوبي ريبر" (CVE-2026-43502)، تتيح لمهاجم محلي تصعيد صلاحياته للجذر عبر بروتوكول "آر دي إس"، وهي موجودة منذ "لينكس 4.17". 📌 للتفاصيل الكاملة: 🔗 https://www.instagram.com/p/DdRbsVXoKck/?stkn=NGcyYmhnZzNmaDBw #ثغرات #لينكس https://t.co/5KB0aa32SB

    Post summary

    Nibosec researchers disclosed a new Linux kernel vulnerability (CVE-2026-43502) named 'Zi Copy Reaper' enabling local privilege escalation via the RDS protocol, affecting kernels since version 4.17.

    0000042
    25 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Breaking: a serious Linux kernel vulnerability named ZcopyReaper (CVE-2026-43502) allows unprivileged users to escalate to root via RDS zero-copy send path flaw. Affects Linux v4.17 onward, even in hardened setups. Patch released in 7.1-rc3; Ubuntu & Debian kernels already backpatched—admins must update. #Linux #Kernel #Security #Vulnerability #RDS #Linux #Kernel #Security #PrivilegeEscalation #RDS #ZcopyReaper https://thedailytechfeed.com/zcopyreaper-critical-linux-kernel-flaw-enables-privilege-escalation/

    Post summary

    The tweet discloses a Linux kernel privilege escalation vulnerability (CVE-2026-43502) and notes that a patch is available in kernel 7.1-rc3 with backports for Ubuntu/Debian, urging administrators to update.

    0000066
    732 followersView on X
  • pd/f/@bitcoin180
    General

    @cybermeowfia CVE-2026-43502 is a real Linux kernel security issue in net/rds, but one detail needs clarification: it’s not openSUSE-only, and the vulnerability is classified as a local attack. The affected SUSE/openSUSE versions should be specified clearly to avoid misleading readers.

    Post summary

    The message confirms CVE-2026-43502 as a local Linux kernel issue in net/rds, clarifies it is not openSUSE‑only, and provides no PoC, exploit, patch, or evidence of active exploitation.

    0000085
    24 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more