https://seclists.org/oss-sec/2026/q3/665: Linux kernel LPEs: Zcopyaper (CVE-2026-43502) and 20 mo
Published Sep 8, 2026
·Updated
Affected Software
1 affected component
Linux Linux kernel>=undefined
Systems with CONFIG_INET and CONFIG_AIO enabled, plus RDS and RDS TCP support enabled either built in or as modules, can reach the vulnerable path. If RDS is modular, rds.ko and rds_tcp.ko must be loaded or available for automatic loading.
An unprivileged local user can trigger the vulnerability. No Linux capabilities are required.
No. CONFIG_USER_NS is not required to exploit the vulnerability, so disabling unprivileged user namespace creation does not mitigate it.
The vulnerability was fixed by commit 44b550d88b26. The first mainline release reported to contain the fix is Linux v7.1-rc3.