CVE-2026-43502 (ZcopyReaper) is a Linux kernel local privilege-escalation flaw in the Reliable Datagram Sockets (RDS) zero-copy send cleanup path. A lifetime-management/use-after-free condition can occur after a failed zero-copy send pins application pages before associating them with a socket queue, allowing an unprivileged local user to obtain root privileges. NebuSec publicly demonstrated the issue on openSUSE kernel 6.4.0-150600.23.100; the reported exploit does not require Linux capabilities or user namespaces, so disabling user namespaces does not mitigate the demonstrated path.
The vulnerability was introduced in Linux v4.17 and fixed upstream by commit 44b550d88b26, first appearing in Linux v7.1-rc3, with fixes reportedly propagated to stable kernel trees. NebuSec released a public ZcopyReaper exploit and said its automated exploit-generation pipeline also produced exploits for 20 additional kernel flaws. No in-the-wild exploitation has been reported. Organizations should deploy vendor kernel updates and determine whether RDS or RDS-over-TCP support is built in, loaded, or can be autoloaded on affected hosts.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
NebuSec published public code for the ZcopyReaper local privilege-escalation exploit for CVE-2026-43502 on September 8, 2026.
NebuSec stated that its automated exploit-generation pipeline had identified and exploited CVE-2026-43502 and 20 additional Linux kernel vulnerabilities, and that exploit material was published in its CyberMeowfia GitHub repository.
On September 7, 2026, NebuSec's Yuan Tan reported CVE-2026-43502, dubbed ZcopyReaper, to the oss-security mailing list. The report described local root escalation by an unprivileged user and a demonstration against openSUSE kernel 6.4.0-150600.23.100.
Ubuntu reported fixes for CVE-2026-43502 in supported kernel versions including 7.0.0-28, 6.8.0-136, and 5.15.0-186. Debian also recorded corrected packages across multiple maintained branches.
Linux kernel commit 44b550d88b26 fixed CVE-2026-43502; Linux 7.1-rc3 was identified as the first mainline release containing the fix. A subsequent public follow-up said the fix had been applied across stable kernel trees.
The RDS zero-copy send cleanup flaw later designated CVE-2026-43502 was reported as having been introduced in Linux kernel version 4.17.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcelinuxsecurity.com
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.