https://seclists.org/oss-sec/2026/q3/678: Linux kernel LPEs: Zcopyaper (CVE-2026-43502) and 20 mo
Published Sep 8, 2026
·Updated
Affected Software
21 affected components
Linux Kernel Linux kernel=CVE-2026-43502
Linux Kernel=CVE-2026-43502
Linux Kernel=CVE-2026-23274
Linux Kernel=CVE-2026-31659
Linux Kernel=CVE-2026-31678
Linux Kernel=CVE-2026-43042
Linux Kernel=CVE-2026-43501
Linux Kernel=CVE-2026-52912
Linux Kernel=CVE-2026-52923
Linux Kernel=CVE-2026-52924
Linux Kernel=CVE-2026-52929
Linux Kernel=CVE-2026-52933
Linux Kernel=CVE-2026-63834
Linux Kernel=CVE-2026-68162
Linux Kernel=CVE-2026-68376
Linux Kernel=CVE-2026-72137
Linux Kernel=CVE-2026-72255
Linux Kernel=CVE-2026-74480
Linux Kernel=CVE-2026-74581
Linux Kernel=CVE-2026-74597
Linux Kernel=CVE-2026-80714
Frequently Asked Questions
1
Which kernel configurations need to be present for this issue to be relevant?
The affected RDS zerocopy send path requires CONFIG_INET=y, CONFIG_AIO=y, CONFIG_RDS set to y or m, and CONFIG_RDS_TCP set to y or m. Systems without RDS and RDS-over-TCP enabled are not described as exposed by the report.
2
Does exploitation require remote network access?
The issue is described as a Linux kernel local privilege escalation vulnerability. The provided information does not describe a remote exploitation path.
3
What can reduce exposure before a fix is available?
Avoid enabling or loading the RDS and RDS-over-TCP functionality where it is not needed. The discussion also notes that locking kernel module loading after boot can help prevent obscure networking modules from being loaded later.