PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43502 Linux CVE debrief

A vulnerability in the Linux kernel's RDS (Reliable Datagram Service) subsystem can lead to improper handling of zerocopy send cleanup, potentially causing issues with pinned user pages and message queuing. This issue arises when a zerocopy send fails after user pages have been pinned but before the message is attached to the sending socket. The purge path may incorrectly infer zerocopy state, leading to improper cleanup of pinned page accounting. Linux kernel maintainers and users should assess exposure and prioritize patching vulnerable kernel versions to prevent potential issues.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-09-15
Advisory published
2026-05-21
Advisory updated
2026-09-15

Who should care

Linux kernel maintainers, users, and administrators should assess exposure and prioritize patching vulnerable kernel versions. Affected operators, platforms, vulnerability-management, and security teams should review system configurations and kernel versions to determine potential impact and implement necessary mitigations.

Why it matters

A vulnerability in the Linux kernel's RDS subsystem can lead to improper handling of zerocopy send cleanup, potentially causing issues with pinned user pages and message queuing. Linux kernel maintainers and users should assess exposure and prioritize patching vulnerable kernel versions.

  • Verify and apply patches to vulnerable kernel versions to prevent potential issues with RDS and zerocopy sends
  • Review system configurations and kernel versions to assess exposure
  • Monitor system logs for potential issues related to RDS and zerocopy sends

Technical summary

The Linux kernel's RDS subsystem has a vulnerability related to zerocopy send cleanup. When a zerocopy send fails after user pages have been pinned but before the message is attached to the sending socket, the purge path may incorrectly infer zerocopy state. This can lead to improper cleanup of pinned page accounting. The fix captures op_mmp_znotifier upfront in rds_message_purge() and uses it as the cleanup discriminator.

Defensive priority

Linux kernel maintainers and users should assess exposure and prioritize patching vulnerable kernel versions.

Recommended defensive actions

  • Assess exposure by reviewing system configurations and kernel versions
  • Prioritize patching vulnerable kernel versions
  • Monitor system logs for potential issues related to RDS and zerocopy sends
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD details provide information on the vulnerability, its CVSS score, and affected kernel versions. The fix captures op_mmp_znotifier upfront in rds_message_purge() and uses it as the cleanup discriminator. Evidence is limited to publicly available details from the CVE Program and NVD. Defenders should verify affected kernel versions, review system configurations, and monitor system logs for potential issues related to RDS and zerocopy sends.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43502 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43502

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43502 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43502

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0f5c185fc79a59ee9991234dd6d2a3e5afa6e75b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/14ef6fd18db2494098b21e0471bf27a1d8e9993e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1e262db7675e27f42c3f3f47d6011855f4454f24

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/21d70744e6d3bbf9293aa1ee6fba7c53ad75275e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3abc8983b2bae3f487f77d9da5527d7d6b210d46

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/44b550d88b267320459d518c0743a241ab2108fa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/46662f7dc59475995609bf3e9d27eb36f4acf26f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e9aefdc5c53fe9aed108c14e3d155710a1bb14c9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.