PatchSiren cyber security CVE debrief
CVE-2026-43502 Linux CVE debrief
A vulnerability in the Linux kernel's RDS (Reliable Datagram Service) subsystem can lead to improper handling of zerocopy send cleanup, potentially causing issues with pinned user pages and message queuing. This issue arises when a zerocopy send fails after user pages have been pinned but before the message is attached to the sending socket. The purge path may incorrectly infer zerocopy state, leading to improper cleanup of pinned page accounting. Linux kernel maintainers and users should assess exposure and prioritize patching vulnerable kernel versions to prevent potential issues.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-09-15
Who should care
Linux kernel maintainers, users, and administrators should assess exposure and prioritize patching vulnerable kernel versions. Affected operators, platforms, vulnerability-management, and security teams should review system configurations and kernel versions to determine potential impact and implement necessary mitigations.
Why it matters
A vulnerability in the Linux kernel's RDS subsystem can lead to improper handling of zerocopy send cleanup, potentially causing issues with pinned user pages and message queuing. Linux kernel maintainers and users should assess exposure and prioritize patching vulnerable kernel versions.
- Verify and apply patches to vulnerable kernel versions to prevent potential issues with RDS and zerocopy sends
- Review system configurations and kernel versions to assess exposure
- Monitor system logs for potential issues related to RDS and zerocopy sends
Technical summary
The Linux kernel's RDS subsystem has a vulnerability related to zerocopy send cleanup. When a zerocopy send fails after user pages have been pinned but before the message is attached to the sending socket, the purge path may incorrectly infer zerocopy state. This can lead to improper cleanup of pinned page accounting. The fix captures op_mmp_znotifier upfront in rds_message_purge() and uses it as the cleanup discriminator.
Defensive priority
Linux kernel maintainers and users should assess exposure and prioritize patching vulnerable kernel versions.
Recommended defensive actions
- Assess exposure by reviewing system configurations and kernel versions
- Prioritize patching vulnerable kernel versions
- Monitor system logs for potential issues related to RDS and zerocopy sends
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD details provide information on the vulnerability, its CVSS score, and affected kernel versions. The fix captures op_mmp_znotifier upfront in rds_message_purge() and uses it as the cleanup discriminator. Evidence is limited to publicly available details from the CVE Program and NVD. Defenders should verify affected kernel versions, review system configurations, and monitor system logs for potential issues related to RDS and zerocopy sends.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43502 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43502
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43502 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43502
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0f5c185fc79a59ee9991234dd6d2a3e5afa6e75b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/14ef6fd18db2494098b21e0471bf27a1d8e9993e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1e262db7675e27f42c3f3f47d6011855f4454f24
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/21d70744e6d3bbf9293aa1ee6fba7c53ad75275e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3abc8983b2bae3f487f77d9da5527d7d6b210d46
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/44b550d88b267320459d518c0743a241ab2108fa
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/46662f7dc59475995609bf3e9d27eb36f4acf26f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e9aefdc5c53fe9aed108c14e3d155710a1bb14c9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.