CVE-2026-43502
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. However, zerocopy ownership is really determined by the presence of op_mmp_znotifier, regardless of whether the message has reached the socket queue. Capture op_mmp_znotifier up front in rds_message_purge(...
- CVSS
- 7.8
- EPSS
- 0.12% 2.46% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.21