PT-2026-42458 · Linux+2 · Linux Kernel+2

CVE-2026-43502

·

Published

2026-05-21

·

Updated

2026-09-12

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to May 2026
Description An out-of-bounds memory buffer operation exists in the rds message purge() function. The issue occurs during a zerocopy send failure after user pages are pinned but before the message is attached to the sending socket. The purge path incorrectly infers the zerocopy state from rm->m rs, causing unqueued messages to be cleaned up as if they owned normal payload pages. In reality, zerocopy ownership is determined by the presence of op mmp znotifier. This flaw can be exploited remotely to impact the confidentiality, integrity, and availability of protected information. This issue was discovered and exploited by the NebuSec security pipeline.
Recommendations Update the Linux kernel to the version released in May 2026 or later. As a temporary mitigation, restrict the use of the rds message purge() function.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-87075
BDU:2026-08522
CVE-2026-43502
ECHO-7220-A71F-2BCE
OPENSUSE-SU-2026:10859-1
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8618-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8663-1
USN-8664-1
USN-8665-1
USN-8668-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu