Recently, a local privilege escalation vulnerability (CVE-2026-43494, known as PinTheft) has been disclosed in the Linux kernel RDS subsystem. When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), op_nents is not reset while the pinned pages are released. Later, rds_message_purge() iterates over the stale op_nents count and frees the pages again, resulting in a double-free. A local attacker can exploit this to achieve privilege escalation to root.
Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-43494
https://lore.kernel.org/linux-cve-announce/2026052130-CVE-2026-43494-a65a@gregkh/
important
(Severity: low, medium, important, and critical)
4.17 <= Linux kernel < 5.10.258
5.11 <= Linux kernel < 5.15.209
5.16 <= Linux kernel < 6.1.175
6.2 <= Linux kernel < 6.6.141
6.7 <= Linux kernel < 6.12.91
6.13 <= Linux kernel < 6.18.33
6.19 <= Linux kernel < 7.0.10
All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.
Linux Kernel 5.10 >= 5.10.258 (commit c6e51512a784)
Linux Kernel 5.15 >= 5.15.209 (commit 03014551938a)
Linux Kernel 6.1 >= 6.1.175 (commit d84ce1786ce4)
Linux Kernel 6.6 >= 6.6.141 (commit 9115669faedc)
Linux Kernel 6.12 >= 6.12.91 (commit 0bbbff00a15b)
Linux Kernel 6.18 >= 6.18.33 (commit 640e37f58f99)
Linux Kernel 7.0 >= 7.0.10 (commit 290e833d1acb)
Linux Kernel 7.1 (commit e17492979319, original fix)
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://git.kernel.org/stable/c/c6e51512a784c4a7b86e1a044988696e3b3721fa
https://git.kernel.org/stable/c/03014551938a0887fa55f18ce49b70158a9c0113
https://git.kernel.org/stable/c/d84ce1786ce40fdd3dd98db47aec5527817e1ef6
https://git.kernel.org/stable/c/9115669faedccdda100428e2d26fd0aac8c50799
https://git.kernel.org/stable/c/0bbbff00a15b1df2cac9014d6cf4b6890f473353
https://git.kernel.org/stable/c/640e37f58f991546a87540d067279c2c1fa9fe51
https://git.kernel.org/stable/c/290e833d1acb1093bc121fcdc97f5e6161157479
https://git.kernel.org/stable/c/e174929793195e0cd6a4adb0cad731b39f9019b4
For details about the fixed versions of Linux vendors, see the security notices of Amazon Linux, Oracle Linux, Red Hat, SUSE and Ubuntu.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us