PT-2026-42451 · Linux+3 · Linux Kernel+3

·

CVE-2026-43494

·

Published

2025-05-05

·

Updated

2026-08-30

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A double-free issue exists in the net/rds module of the Linux kernel. The problem occurs when a zerocopy page pin operation fails within the rds message zcopy from user() function, specifically when iov iter get pages2() fails. In this scenario, while pinned pages are released and rm->data.op mmp znotifier is cleared, the memory management counter op nents is not correctly reset. Subsequently, when rds sendmsg() calls the rds message purge() function, the cleanup loop uses the incorrect non-zero value of op nents to release memory that has already been freed. A local attacker could exploit this to cause a system crash (denial of service), escalate privileges, or execute unauthorized code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the net/rds module to minimize the risk of exploitation.

Exploit

DoS

Double Free

Multiple Releases of Same Resource or Handle

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-87083
BDU:2026-07273
CVE-2026-43494
ECHO-ABBB-9356-9662
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
SUSE-SU-2026:22598-1
SUSE-SU-2026:22673-1
SUSE-SU-2026:22674-1
SUSE-SU-2026:22675-1
SUSE-SU-2026:22676-1
SUSE-SU-2026:22677-1
SUSE-SU-2026:22678-1
SUSE-SU-2026:22680-1
SUSE-SU-2026:22681-1
SUSE-SU-2026:22682-1
SUSE-SU-2026:22683-1
SUSE-SU-2026:22684-1
SUSE-SU-2026:22685-1
SUSE-SU-2026:22686-1
SUSE-SU-2026:22687-1
SUSE-SU-2026:22689-1
SUSE-SU-2026:22690-1
SUSE-SU-2026:22691-1
SUSE-SU-2026:22692-1
SUSE-SU-2026:22693-1
SUSE-SU-2026:22694-1
SUSE-SU-2026:22695-1
SUSE-SU-2026:22696-1
SUSE-SU-2026:22697-1
SUSE-SU-2026:22711-1
SUSE-SU-2026:22712-1
SUSE-SU-2026:22713-1
SUSE-SU-2026:22714-1
SUSE-SU-2026:22715-1
SUSE-SU-2026:22716-1
SUSE-SU-2026:22717-1
SUSE-SU-2026:22718-1
SUSE-SU-2026:22719-1
SUSE-SU-2026:22720-1
SUSE-SU-2026:22721-1
SUSE-SU-2026:22722-1
SUSE-SU-2026:22723-1
SUSE-SU-2026:22725-1
SUSE-SU-2026:22726-1
SUSE-SU-2026:22728-1
SUSE-SU-2026:22729-1
SUSE-SU-2026:22730-1
SUSE-SU-2026:22731-1
SUSE-SU-2026:22732-1
SUSE-SU-2026:22733-1
SUSE-SU-2026:22734-1
SUSE-SU-2026:22735-1
SUSE-SU-2026:22743-1
SUSE-SU-2026:22744-1
SUSE-SU-2026:22746-1
SUSE-SU-2026:22747-1
SUSE-SU-2026:22748-1
SUSE-SU-2026:22749-1
SUSE-SU-2026:22755-1
SUSE-SU-2026:22758-1
SUSE-SU-2026:22759-1
SUSE-SU-2026:22761-1
SUSE-SU-2026:22762-1
SUSE-SU-2026:22763-1
SUSE-SU-2026:22775-1
SUSE-SU-2026:22776-1
SUSE-SU-2026:22777-1
SUSE-SU-2026:22778-1
SUSE-SU-2026:22780-1
SUSE-SU-2026:22781-1
SUSE-SU-2026:22782-1
SUSE-SU-2026:22783-1
SUSE-SU-2026:22784-1
SUSE-SU-2026:22785-1
SUSE-SU-2026:22786-1
SUSE-SU-2026:22792-1
SUSE-SU-2026:22793-1
SUSE-SU-2026:22794-1
SUSE-SU-2026:22795-1
SUSE-SU-2026:22864-1
SUSE-SU-2026:22865-1
SUSE-SU-2026:22867-1
SUSE-SU-2026:22868-1
SUSE-SU-2026:22869-1
SUSE-SU-2026:22870-1
SUSE-SU-2026:22872-1
SUSE-SU-2026:22873-1
SUSE-SU-2026:22874-1
SUSE-SU-2026:22875-1
SUSE-SU-2026:22876-1
SUSE-SU-2026:22877-1
SUSE-SU-2026:22912-1
SUSE-SU-2026:22913-1
SUSE-SU-2026:22914-1
SUSE-SU-2026:22915-1
SUSE-SU-2026:2855-1
SUSE-SU-2026:2857-1
SUSE-SU-2026:2858-1
SUSE-SU-2026:2864-1
SUSE-SU-2026:2866-1
SUSE-SU-2026:2867-1
SUSE-SU-2026:2868-1
SUSE-SU-2026:2887-1
SUSE-SU-2026:2888-1
SUSE-SU-2026:2889-1
SUSE-SU-2026:2890-1
SUSE-SU-2026:2894-1
SUSE-SU-2026:2895-1
SUSE-SU-2026:2899-1
SUSE-SU-2026:2902-1
SUSE-SU-2026:2910-1
SUSE-SU-2026:2920-1
SUSE-SU-2026:2930-1
SUSE-SU-2026:2932-1
SUSE-SU-2026:2933-1
SUSE-SU-2026:2937-1
SUSE-SU-2026:2938-1
SUSE-SU-2026:2943-1
SUSE-SU-2026:2945-1
SUSE-SU-2026:2956-1
SUSE-SU-2026:2957-1
SUSE-SU-2026:2961-1
USN-8370-1
USN-8371-1
USN-8373-1
USN-8374-1
USN-8388-1
USN-8388-2
USN-8389-1
USN-8391-1
USN-8392-1
USN-8393-1
USN-8426-1
USN-8426-2
USN-8440-1
USN-8461-1
USN-8462-1
USN-8489-1
USN-8497-1
USN-8499-1
USN-8528-1
USN-8569-1
USN-8616-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Ubuntu