Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
September 14, 2026
WhatsApp’s Restricted Chat Feature Improves Privacy and Security
September 14, 2026
Critical Sogou Input Method RCE Vulnerability Lets Attackers Backdoor Users
September 14, 2026
Home/CyberSecurity News/New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
CyberSecurity News

New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks

Key Takeaways A critical local privilege escalation vulnerability, CVE-2026-43502 (ZcopyReaper), has been discovered in the Linux kernel. The flaw impacts the Reliable Datagram Sockets (RDS)...

Sarah simpson
Sarah simpson
September 14, 2026 3 Min Read
2 0

Key Takeaways

  • A critical local privilege escalation vulnerability, CVE-2026-43502 (ZcopyReaper), has been discovered in the Linux kernel.
  • The flaw impacts the Reliable Datagram Sockets (RDS) zero-copy send path and affects kernels dating back to version 4.17.
  • Successful exploitation allows an unprivileged local attacker to gain root-level control, bypassing common hardening techniques like disabling unprivileged user namespaces.
  • Patches are available in Linux 7.1-rc3 and have been backported to various stable distributions, including Ubuntu and Debian.

New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks

A significant vulnerability, designated ZcopyReaper, has been identified in the Linux kernel, potentially allowing local attackers to escalate privileges to root. This flaw, tracked as CVE-2026-43502, resides within the Reliable Datagram Sockets (RDS) zero-copy send path and has been present in the kernel since version 4.17.

Table Of Content

  • Key Takeaways
  • New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
  • Technical Details of CVE-2026-43502
  • Exploitation and System Requirements
  • Patch and Mitigation
  • What You Should Do

Security researchers at NebuSec successfully demonstrated the ZcopyReaper exploit, highlighting its practical implications beyond mere denial-of-service. Their disclosure published in Openwall detailed a successful demonstration on an openSUSE installation running kernel version 6.4.0-150600.23.100.

Technical Details of CVE-2026-43502

The core of the ZcopyReaper vulnerability lies in an improper memory cleanup routine. Specifically, when an RDS zero-copy send operation fails after user-space pages have been pinned but before the associated message is linked to the sending socket, the system mishandles memory. The affected purge path incorrectly determines the cleanup method based on the message’s socket association, rather than verifying zero-copy ownership via the presence of the op_mmp_znotifier structure.

This logical error means a message not yet enqueued to a socket can be treated as if it contained ordinary payload pages during cleanup. This mismanaged lifecycle can lead to kernel memory corruption, creating conditions ripe for local privilege escalation.

Exploitation and System Requirements

A critical aspect of ZcopyReaper is that its exploitation does not necessitate specific Linux capabilities or access to unprivileged user namespaces. This means that common hardening strategies, such as disabling unprivileged user namespace creation, are ineffective against this particular attack vector.

For a system to be vulnerable, several kernel configurations must be enabled: CONFIG_INET and CONFIG_AIO, along with CONFIG_RDS and CONFIG_RDS_TCP. These RDS components can either be compiled directly into the kernel or exist as loadable modules. In modular setups, the rds.ko and rds_tcp.ko modules must be loaded or accessible via automatic module loading for an attacker to reach the vulnerable code path.

Patch and Mitigation

The vulnerability has been addressed upstream with commit 44b550d88b26, with Linux 7.1-rc3 being the first mainline release to incorporate the fix. Major distributions have also begun backporting the patch. Ubuntu, for instance, has released fixes for kernels including 7.0.0-28, 6.8.0-136, and 5.15.0-186. Debian has also updated packages across its maintained branches.

NebuSec further noted that their automated exploit-generation pipeline not only confirmed ZcopyReaper’s exploitability but also produced public exploits for 20 other Linux kernel vulnerabilities, which are available in their CyberMeowfia security-research repository. This underscores the immediate need for system administrators to assess and update their environments.

What You Should Do

  • Apply Kernel Updates: Immediately install vendor-provided kernel updates that include the fix for CVE-2026-43502.
  • Reboot Systems: After applying updates, reboot your systems into the newly patched kernel and verify the running version.
  • Evaluate RDS Usage: If immediate patching is not feasible, determine whether Reliable Datagram Sockets (RDS) and RDS-over-TCP are essential for your operations. If not, prevent the unnecessary rds.ko and rds_tcp.ko modules from loading.
  • Do Not Rely on User Namespace Restrictions: Be aware that disabling unprivileged user namespaces is not an effective mitigation strategy for ZcopyReaper.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

WhatsApp’s Restricted Chat Feature Improves Privacy and Security

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Exploit Claude AI to Steal Data from 1.8M Android Apps
September 14, 2026
Critical RCE Flaw in GitHub Enterprise Server Patched, Bounty Awarded
September 14, 2026
Hackers Exploit YouTube Gaming Channels, SEO Poisoning to Deploy RATs
September 14, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us