CVE-2026-52929Exploit(linux / linux_kernel)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and then lowers outcnt. That leaves removed stream metadata behind, so a later re-add can reuse a stale ext and hit a null-pointer dereference in the scheduler get path. Fix the rollback by tearing down the removed stream state the same way other stream resizes do. Unschedule the current scheduler state, drop the removed stream ext state with sctp_stream_outq_migrate(), and then reschedule the remaining streams. This keeps scheduler-private RR/FC/PRIO lists consistent while fully rolling back denied outgoing stream additions.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-08-21); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 6d
01345Mentions · 2026-08-20: 1Mentions · 2026-08-21: 5Mentions · 2026-08-31: 1Mentions · 2026-09-08: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-21: 5PoC Mentioned / Linked · 2026-08-31: 1Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-21: 4Exploit Tool / Code · 2026-08-31: 1Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-09-12: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 4Technical Details · 2026-08-31: 1Technical Details · 2026-09-15: 108-2008-2108-3109-0809-1209-15
Signal classification4 categories
Exploit
440.0%
PoC
330.0%
General
220.0%
Patch
110.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-08-201
Exploit1
2026-08-215
Exploit2PoC3
2026-08-311
Exploit1
2026-09-081
General1
2026-09-121
General1
2026-09-151
Patch1
Full discourse10 posts
  • Nebula Security@nebusecurity
    Exploit

    Today's exploit is for Ubuntu 26.04, an SCTP type confusion, CVE-2026-52929, classified as null-ptr-deref. It was introduced in Oct 2017 and fixed upstream in Jun 2026. Discovered and exploited by the NebuSec security pipeline. Exploit source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52929-Ubuntu-7.0.0-28 https://t.co/Li23WxW4fA

    Post summary

    The content announces an exploitation of Ubuntu 26.04, shares the exploit source code, confirms active usage by NebuSec, provides detailed vulnerability attributes, and notes a vendor patch.

    51941424819.1K
    6.9K followersView on X
  • Cyber Meowfia@cybermeowfia
    Exploit

    Aug 20: Today’s Ubuntu26.04 exploit is from a sctp type-confusion, CVE-2026-52929 (classified as null-ptr-deref). It was introduced in Oct 2017, fixed on upstream in Jun 2026. Discovered and exploit by NebuSec security pipeline. Exploit in our GitHub: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52929-Ubuntu-7.0.0-28 https://t.co/twnqozvtfi

    Post summary

    The text announces the release of an exploit for CVE-2026-52929, an SCTP type-confusion vulnerability in Ubuntu, and shares a link to the functional exploit code on GitHub.

    0502972.5K
    439 followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-52929 Vendor: Linux Product: Linux kernel Description: An issue exists in the SCTP implementation where the system fails to fully roll back the state when an ADD OUT STREAMS request is denied. In such cases, the system only shrinks queued chunks and lowers the outcnt variable, leaving behind removed stream metadata. This allows a subsequent re-addition attempt to reuse a stale extension, leading to a null-pointer dereference within the scheduler get path. A null-pointer dereference occurs when the software attempts to read from a memory address that is null, typically resulting in a system crash/LPE. Link: https://github.com/NebuSec/CyberMeowfia/blob/main/security-research/Linux-CVE-2026-52929-Ubuntu-7.0.0-28/confuse.c #dbugs_vuln

    Post summary

    A publicly available proof‑of‑concept exploit for CVE‑2026‑52929 is demonstrated via GitHub code, showing a null‑pointer dereference in the Linux kernel SCTP module, with no evidence of active exploitation or release of a patch.

    3402261.2K
    3.6K followersView on X
  • yousukezan@yousukezan
    PoC

    LinuxカーネルのSCTP処理に存在する脆弱性CVE-2026-52929についてPoCが公開された。状態のロールバック不備を悪用し、カーネルクラッシュによるDoSを引き起こせるほか、Ubuntu 26.04ではroot権限への昇格も実証されている。 脆弱性はSCTPで送信ストリーム追加要求が拒否された際、ストリーム数などを戻しても古いメタデータが残ることに起因する。後からストリームを再追加すると、この古い情報が再利用され、スケジューラがNULLポインタを参照してカーネルがクラッシュする。Nebula Securityは公開GitHubリポジトリでPoCと技術詳細を公開し、未修正のUbuntu環境でroot権限を取得するデモ動画も示した。問題のコードは2017年10月に導入され、複数の長期サポート系統に影響する。上流では2026年6月に修正済みで、各Linuxディストリビューションの修正済みカーネルへの更新が必要となる。記事執筆時点で実際の悪用は確認されていない。 https://securityonline.info/cve-2026-52929-sctp-privilege-escalation/

    Post summary

    Nebula Security released a PoC and technical details for CVE‑2026‑52929, demonstrating kernel crash and root escalation on unpatched Ubuntu, though no real‑world exploitation has been reported and a patch is available in updated kernels.

    040951.7K
    15.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🔴 Nebula Security, Linux kernel'deki CVE-2026-52929 açığı için Ubuntu 26.04 üzerinde çalışan bir yerel yetki yükseltme (LPE) exploit'i yayınladı. Bu açık Haziran 2026'da upstream'de düzeltildi. PoC: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52929-Ubuntu-7.0.0-28 https://x.com/nebusecurity/status/2090585257540259971/video/1

    Post summary

    Nebula Security released a working local privilege escalation exploit for CVE-2026-52929 on Ubuntu 26.04, providing a PoC and noting the vulnerability was fixed upstream in June 2026.

    030112657
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Exploit

    Public PoC exploit code for CVE-2026-52929, a Linux kernel SCTP flaw, escalates to root. Full vulnerability details are now disclosed. #CVE202652929 #LinuxKernel #SCTP #PrivilegeEscalation #PoC #infosec https://securityonline.info/cve-2026-52929-sctp-privilege-escalation/

    Post summary

    The post announces that public PoC exploit code for CVE‑2026‑52929, a Linux kernel SCTP flaw that grants root privileges, is now available, but does not mention active exploitation, patches, or technical specifics.

    01072505
    13.0K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The entry compiles a list of recent CVEs, highlighting active exploitation of MikroTik RouterOS and noting patch gaps for ShieldBreak, but offers limited technical depth or exploit detail.

    01052600
    3.4K followersView on X
  • Brad Spengler@spendergrsec
    General

    For oss-sec: CVE-2026-72137 needs xfrm, CVE-2026-52933 needs io_uring, CVE-2026-52929 needs sctp, CVE-2026-43502 needs rds (is what the original post was about)

    Post summary

    The post briefly lists four CVE identifiers along with the subsystems they require, without providing additional technical details, exploitation information, or mitigation guidance.

    00042767
    7.1K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    The text discloses CVE-2026-43502 as a Linux kernel local privilege-escalation bug and lists multiple related CVEs, but its main actionable item is that the issue was fixed by commit 44b550d88b26 in Linux v7.1-rc3. It notes public exploits are available, but does not name a specific exploit tool or report active exploitation.

    0002055
    91 followersView on X
  • moton@moton
    PoC

    CVE-2026-52929: PoC for SCTP Privilege Escalation - https://securityonline.info/cve-2026-52929-sctp-privilege-escalation/

    Post summary

    The text announces a PoC for an SCTP privilege‑escalation vulnerability, linking to detailed proof‑of‑concept code, with no mention of patches or active exploitation.

    0000062
    753 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more