Junglewise Threat Intelligence

CVE-2026-43502: Linux Kernel RDS resource leak in zerocopy send cleanup

CVE-2026-43502 · Severity: info · CVSS 0 · Published 2026-05-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Reliable Datagram Sockets (RDS) protocol could lead to inconsistent memory accounting or resource leaks. The issue occurs when a high-performance data transfer method (zerocopy) fails early in the process, causing the system to incorrectly clean up memory resources. This primarily affects system stability and resource management in environments using RDS.

Technical details

A vulnerability in net/rds occurs because the rds_message_purge() function incorrectly infers zerocopy state from the message's socket association (rm->m_rs) rather than the presence of the zerocopy notifier (op_mmp_znotifier). If a zerocopy send fails after user pages are pinned but before the message is queued to a socket, the purge path may treat the message as a normal payload. This results in a failure to properly unaccount pinned pages and release the notifier. The fix ensures that op_mmp_znotifier is used as the primary discriminator for cleanup, ensuring consistent resource release regardless of whether the message reached the socket queue.

Affected products

  • Linux Linux Kernel Fixed in 0f5c185, 14ef6fd, 21d7074, 3abc898, 44b550d

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory

References