Skip to main content
QUIETLYTIC
Vulnerability

Linux Kernel Vulnerability (CVE-2026-43494)

CVE-2026-43494 is a CVSS 7.8 Linux kernel double-free in the RDS networking subsystem, reported exploited by VulnCheck alone.

CVE-2026-43494
Threat Level
HIGH
CVSS
7.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Linux Kernel

CVE-2026-43494 carries a CVSS 3.1 base score of 7.8 against the Linux kernel. NVD classifies it as CWE-1341 (Multiple Releases of Same Resource or Handle). VulnCheck’s KEV feed reports the CVE as exploited, dated August 26, 2026, and titles its entry a “Linux Kernel ‘net/rds’ Local Privilege Escalation.”

That exploitation report is single-sourced. CISA has not added CVE-2026-43494 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description, sourced from the upstream kernel fix commit, locates the bug in the Reliable Datagram Sockets (RDS) protocol implementation’s zero-copy send path. NVD states that when a call to pin the user’s memory pages fails partway through preparing a zero-copy message, the kernel releases the already-pinned pages and clears one internal tracking field, but fails to reset a second field that counts how many memory regions are associated with the message. NVD states a later cleanup pass then iterates over that stale, non-zero count and releases the same pages a second time — a double-free of kernel-managed memory resources.

We are reporting the nature of this double-free and its consequence rather than the specific socket call sequence needed to trigger the failure path, which is available in the upstream kernel commit NVD cites for readers who need it for patch verification.

Evidence and confidence

  • Medium confidence — the CVSS 7.8 score, the vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the CWE-1341 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by the upstream kernel fix commits NVD links. The exploitation report traces to VulnCheck KEV alone.
  • Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00299, a 22.6th percentile score as of our ingestion.

No field is in conflict between our two sources. Our data carries no single fixed-version field; the upstream kernel commits NVD links identify the corrected code across multiple stable kernel branches.

Why this matters

Double-free vulnerabilities in kernel networking code are a well-established class of bug used for local privilege escalation, since freeing the same memory region twice can let an attacker manipulate what gets allocated into that region on a subsequent allocation, corrupting kernel data structures under attacker influence. VulnCheck’s own naming of this entry as a local privilege escalation reflects that standard pattern. Like other kernel entries in this cycle’s coverage, this flaw is local (AV:L) rather than remotely reachable, making it best suited as a follow-on step for an attacker who already has limited local code execution on a Linux host.

Frequently Asked Questions

What is CVE-2026-43494? A CVSS 7.8 double-free vulnerability (CWE-1341) in the Linux kernel’s Reliable Datagram Sockets (RDS) zero-copy send path, triggered when a memory-pinning failure leaves a stale resource count that a later cleanup pass acts on twice.

Is CVE-2026-43494 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 26, 2026, and characterizes it as a local privilege escalation. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need remote network access to exploit this? No. The CVSS vector specifies a local attack vector requiring low privileges — this is a local kernel memory-corruption flaw, not a remotely reachable one.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which kernel versions fix this? Our source data carries no single fixed-version field. Consult the upstream kernel fix commits linked from NVD’s record, or your Linux distribution’s own security errata, for the specific version that includes the fix.


Severity, weakness classification, and mechanism sourced from the National Vulnerability Database record for CVE-2026-43494 and the linked upstream Linux kernel fix commit. Exploitation status and the August 26, 2026 catalog date, and the local-privilege-escalation characterization, reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools