Researchers from Nebula Security uncovered details about 18 vulnerabilities in the Linux kernel and prepared exploits that allow an unprivileged local user to obtain root rights in the system. The vulnerabilities have been resolved in various spring and summer kernel updates. Identified issues:
- CVE-2026-43502 (exploit) — a vulnerability in the RDS (Reliable Datagram Sockets) network subsystem, caused by improper clearing of pinned memory pages during a failure to send data in zerocopy mode before queuing the message. The issue was code-named ZcopyReaper, and appears starting from kernel version 4.17, fixed in the kernel in May. Exploitation of this vulnerability is possible on systems with a kernel compiled with the options CONFIG_INET=y, CONFIG_AIO=y, CONFIG_RDS=y|m and CONFIG_RDS_TCP=y|m (typically set by default). No privileges to work with user identifier namespaces are required for the attack. The exploit has been demonstrated in openSUSE with the standard kernel 6.4.
- CVE-2026-80714 (exploit) — a vulnerability in the IPVS (IP Virtual Server) subsystem, caused by accessing memory after it has been freed due to mistakenly setting the IP_VS_CONN_F_ONE_PACKET flag during connection synchronization, which after the connection's timeout leads to dangling pointers remaining in the hash table, pointing to an already freed ip_vs_conn structure. The issue was fixed on August 19. The exploit has been demonstrated in Debian 13 with kernel 6.12.
- CVE-2026-74597 (exploit) — a vulnerability in the ip6_tunnel driver, caused by incorrect application of offsets to the encapsulated packet for the HAO (Home Address Option), calculated based on the external packet. By sending an encapsulated packet with a specially crafted header, it is possible to achieve data writes beyond the allocated buffer. The issue was fixed on August 19. The exploit has been demonstrated in CentOS with kernel 6.12.
- CVE-2026-74581 (exploit) — a vulnerability in the code handling IPv6 routing tables, caused by accessing memory after it has been freed (after freeing memory for a route, an active pointer to that route remained). The issue was fixed on August 19. The exploit has been demonstrated in Debian 13 with kernel 6.12.
- CVE-2026-74480 (exploit) — a vulnerability in the network bridge subsystem, caused by a use-after-free access in the multicast group exit code (after removing an element from the linked list, the loop did not stop, and during iterations, there was access through a pointer to the port list that remained after removal). The issue was resolved on August 9. The exploit was demonstrated in RHEL 10 with kernel 6.12.
- CVE-2026-72255 (exploit) — a vulnerability in the nf_queue module of the netfilter subsystem, caused by a use-after-free memory access that occurs if, after the removal of a network bridge, the associated packet is still in the NFQUEUE. The issue was resolved on July 24. The exploit was demonstrated in Ubuntu 26.04 with kernel 7.0.
- CVE-2026-72137 (exploit) — a vulnerability in the IPSec XFRM module, leading to a double free of the skb structure upon an error in sending a keepalive packet. The issue was resolved on June 30. The exploit was demonstrated in Ubuntu 26.04 with kernel 7.0.
- CVE-2026-68376 (exploit) — a vulnerability in the SCTP protocol implementation, leading to a buffer overflow due to an incorrect calculation of the array size for storing HMAC identifiers. The issue was resolved on August 3. The exploit was demonstrated in Ubuntu 26.04 with kernel 7.0.
- CVE-2026-68162 (exploit) — a vulnerability in the SCTP protocol implementation, leading to a use-after-free access when attempting to modify a sysctl parameter after the controlling socket has been closed. The issue was resolved on April 10. The exploit was demonstrated in Ubuntu 26.04 with kernel 7.0.
- CVE-2026-64560 (exploit) — a vulnerability in posix-cpu-timer, leading to a use-after-free access due to a race condition between timer deletion and an exec() call after changing the thread group leader. The issue was resolved on July 5. The exploit was demonstrated on a Google Pixel device running Android.
- CVE-2026-52933 (exploit) — a vulnerability in the io_uring subsystem, leading to a use-after-free access when the IO_POLL_CANCEL_FLAG is set due to interpreting the atomic_read() value as a negative number when compared to the reference counter. The issue was resolved on April 15. The exploit was demonstrated in Fedora Linux with kernel 6.19.
- CVE-2026-52924 (exploit) — a vulnerability in the implementation of the SCTP protocol that leads to a use-after-free condition due to an active pointer and data remaining in the send queue after the stream table is freed following a 'Stale Cookie' error. The issue was resolved on June 19. The exploit was demonstrated on Ubuntu 26.04 with kernel 7.0.
- CVE-2026-52923 (exploit) — a vulnerability in the SysV IPC subsystem that results in a use-after-free condition due to a dangling pointer to a freed index element remaining in the IDR structure. The issue was resolved on July 24. The exploit was demonstrated on RHEL 10 with kernel 6.12.
- CVE-2026-52912 (exploit) — a vulnerability in the nf_queue module of the netfilter subsystem caused by a use-after-free condition due to incorrect handling of a pointer after the removal of a network bridge while associated packets are present in the NFQUEUE. The issue was resolved on June 1. The exploit was demonstrated on openSUSE with kernel 6.4.
- CVE-2026-43501 (exploit) — a vulnerability in the IPv6 SRH (Source Routing Header) header unpacking code, leading to an out-of-bounds write due to the lack of checks on conditions under which the new header may exceed the old one. The issue was resolved on May 7. The exploit was demonstrated at the kernelCTF competition.
- CVE-2026-43042 (exploit) — a vulnerability in the MPLS mechanism that leads to reading data out of bounds due to a race condition occurring when simultaneously reading a lock and resizing a table. The issue was resolved on April 11. The exploit was demonstrated on Debian 13 with kernel 6.12.
- CVE-2026-31678 (exploit) — a vulnerability in the openvswitch subsystem caused by a use-after-free condition due to a race condition when removing a link to a network device before the RCU (Read-Copy-Update) cycle completes. The issue was resolved on April 2. The exploit was demonstrated on Fedora Linux 44 with kernel 6.19.
- CVE-2026-31659 (exploit) — a vulnerability in the implementation of the B.A.T.M.A.N. (Better Approach to Mobile Ad-hoc Networking) protocol leading to a buffer overflow due to integer overflow caused by using 16-bit values while calculating the buffer size. The issue was resolved on April 18. The exploit was demonstrated on Arch Linux with kernel 6.19.
Source: opennet.ru
