ZcopyReaper Is in RDS Zerocopy. User Namespaces Will Not Save You

CVE-2026-43502 is a local root in the RDS zerocopy path, present since Linux 4.17. Mainline fix is 7.1-rc3. Ubuntu lists 7.0.0-28, 6.8.0-136, and 5.15.0-186. Restricting user namespaces does nothing.

Prerequisites

  • Shell access to list kernel config and loaded modules
  • Permission to schedule a kernel update or module blacklist
Compatible with: Linux 4.17 and later until patchedUbuntu kernels listed in distro backports
Server room aisle with a laptop showing a kernel version string, cool fluorescent light, no logos or readable hostnames.

A local unprivileged user and a kernel networking path you probably forgot was compiled in. That is the whole ticket.

GBHackers says CVE-2026-43502 is called ZcopyReaper. Yuan Tan at NebuSec reported it on the OSS Security list. The code path has been in Linux since 4.17. The fix is commit 44b550d88b26. The first mainline release with the fix is 7.1-rc3. NebuSec showed root on an openSUSE box running 6.4.0-150600.23.100. I am not going to describe how.

Yesterday’s GKE Fragnesia note was a container breakout on Ubuntu nodes. This one is a host LPE in RDS. Different door, same advice. Patch. Then check whether the module should have been loadable at all.

RDS zerocopy, not “every Linux box”

ZcopyReaper sits in the Reliable Datagram Sockets zerocopy send path. RDS is the high-performance messaging stack people turn on for clustered databases and a few HPC shops. Most laptops never speak it. Plenty of servers still compile it as a module and then forget.

Cyber Security News puts the bug in rds_message_purge(). The cleanup path did not keep op_mmp_znotifier straight before freeing payload pages. The fix captures the notifier first, then adjusts pinned-page accounting if the message never reached a socket queue. That is as much mechanism as you need to inventory. You do not need a PoC to decide whether rds.ko belongs on a front-end VM.

GBHackers lists the Kconfig minimum:

  • CONFIG_INET=y
  • CONFIG_AIO=y
  • CONFIG_RDS=y or =m
  • CONFIG_RDS_TCP=y or =m

INET and AIO are on in almost every distro kernel you will touch. RDS is the one to grep. If both rds.ko and rds_tcp.ko can load, the path is reachable. GBHackers also warns that automatic module loading can expose the path even when nobody typed modprobe rds. That sentence is the one to send to the people who say “we don’t use RDS.”

I am not publishing exploit steps. GBHackers notes NebuSec’s pipeline found more than twenty exploitable kernel bugs, with PoC material in a research repo named CyberMeowfia, and lists neighboring IDs including CVE-2026-43501 and CVE-2026-43074. Treat that as a reminder that one patch is not a personality. It is not a homework assignment to go collect those PoCs.

User namespaces will not save you

Cyber Press is the piece to forward to anyone whose hardening checklist stops at user.max_user_namespaces = 0. Disabling unprivileged user namespace creation does not mitigate CVE-2026-43502. The RDS zerocopy path does not need CONFIG_USER_NS. The attacker needs local access, not a nested namespace, not a capability you forgot, not a container escape first.

That is the opposite of several 2024-2025 kernel bugs where userns was the on-ramp. If your fleet got those mitigations and then stopped taking kernel updates, you are not covered here.

Local access still means local access. A shared build machine, a university login node, a CI runner that lets pull requests execute, a forgotten jumphost with extra Unix accounts: those are the boxes where “unprivileged local” is not a hypothetical. A locked-down appliance with one admin user and no shells is a lower priority than a login farm. Prioritize anyway. Do not wait for a public dashcam video.

Cyber Press also notes LTS and distro kernels can stay vulnerable when the version string does not look like upstream 7.1-rc3. Correct. uname -r is not a patch oracle. You want the changelog, the USN, or the Debian DSA, not a vibe.

What Ubuntu and Debian have already listed

Cyber Security News says stable trees are backporting. Ubuntu’s listed fixes include 7.0.0-28, 6.8.0-136, and 5.15.0-186. Debian has corrected packages across several maintained branches. If you are on those series, those numbers are the floor. If you are on a vendor kernel (cloud, appliance, Android-ish IoT), you are waiting on that vendor. Do not pretend an Ubuntu ABI number applies to an Amazon or Google custom kernel until the vendor says so.

Ubuntu 24.04.5 shipped a 7.0 LTS story last week. If you jumped to 7.0 and stopped, check whether you actually have 7.0.0-28 or whatever the current security pocket says today. Point releases are not the same as CVE backports.

Mainline 7.1-rc3 is useful if you roll your own. It is not an instruction to put an rc kernel in production so you can say you are “ahead.” Take the distro package.

I am not inventing a CVSS. None of the three write-ups I used printed a NVD score I trust enough to repeat. Call it local root in a maybe-loaded module and move.

Inventory without turning it into a novel

On each class of host, not each host in a 4,000-node fleet if you have configuration management:

uname -r
grep -E 'CONFIG_RDS(_TCP)?=' /boot/config-$(uname -r) 2>/dev/null || zgrep -E 'CONFIG_RDS(_TCP)?=' /proc/config.gz
lsmod | grep -E '^rds'

If config says =y, RDS is in the kernel image and you patch. If =m, check whether the modules are loaded and whether your distro auto-loads them on a socket you did not know you were opening. If is not set, this CVE is not your week, and you should still patch on the next cycle because the neighboring IDs exist.

Blacklisting rds and rds_tcp is a temporary reduction if you do not need the protocol. It is not a substitute for the package that contains 44b550d88b26. Automatic load means a blacklist plus modprobe.d plus a reboot check, not a Slack message that says “please don’t load RDS.”

CI images and container hosts deserve a second look. You do not need RDS inside a builder pod. You do need to know whether the builder’s kernel, which is the host kernel, has the module. The F5 fileless-rootkit piece was about not trusting hashes on middleboxes. This one is about not trusting a kernel defconfig from 2018.

What I would do on Monday

Patch Ubuntu boxes to the versions above or newer. Patch Debian from the security pocket, not from a mirror that still has last month’s meta-package. For RHEL-alikes and SUSE, look up the advisory; the openSUSE PoC kernel in GBHackers is a hint that SUSE trees were reachable, not a complete vendor matrix.

Where RDS is compiled as a module and no application needs it, blacklist it, then patch anyway.

Do not spend the week reproducing NebuSec’s demo. Spend it on the login nodes and the fat CI hosts. Those are where “local unprivileged” is a job title.

What not to do with the disclosure

Do not paste the CyberMeowfia repo into a Slack channel named #fun. GBHackers says NebuSec published proof-of-concept material as part of a larger automated-exploit pipeline. That is a researcher choice. It is not a lab exercise for a junior on-call. If you need to prove exposure, prove it with config and package versions. If a red team insists on a live test, isolate a throwaway VM that matches production’s kernel, not a laptop with your SSH agent.

Do not write a detection rule that looks for “RDS” in logs and call the ticket closed. Successful LPE on the host will not look like an RDS outage. It will look like a local user who should not be root. Watch for unexpected uid 0, unexpected kernel module loads, and hosts that still advertise rds via autoload after you thought you blacklisted it.

Do not skip cloud node images. GKE COS was out of scope for Fragnesia. That does not mean every managed Kubernetes node is out of scope for ZcopyReaper. If the node kernel is Linux 4.17+ with RDS available, you are reading the wrong bulletin if you only bookmarked yesterday’s CVE. Ask the cloud provider for the kernel package ID, not for a blog emoji.

Do not reboot once and skip the second lsmod. Autoload is the point of GBHackers’ warning. A package update that still allows rds_tcp to load on a socket is a half fix. Pair the update with a configuration management check that the modules stay absent on hosts that do not need them.

If you run a mixed estate, write three rows on a whiteboard: Ubuntu 5.15 / 6.8 / 7.0 with the versions Cyber Security News listed, Debian from security, everyone else waiting on a vendor advisory. The openSUSE kernel string in the GBHackers demo is one data point for SUSE shops, not a matrix. Cyber Press is the citation for “userns off is irrelevant.” Keep that citation next to the whiteboard so nobody reopens the 2025 hardening doc and declares victory.

Kernel LPE with a nickname travels faster than the package. The nickname is ZcopyReaper. The work is still a distro update and a reboot window. User namespaces were a good story last year. They are not this CVE. RDS was a good protocol for a small set of clusters. It is a bad surprise on a login node. Patch the nodes that have extra Unix users first. Then patch the rest. Then confirm the module is gone where it never should have been.

A short note on what “local” means in 2026. Shared CI is local. A developer bastion is local. A Jupyter hub is local. A container escape on a noisy neighbor node is a different CVE, but once you are on the host, ZcopyReaper is back in play if RDS can load. Do not wait for a worm. This class of bug usually shows up first as a privilege mistake on a box you already suspected.

If you cannot patch this week, reduce autoload, restrict who can log in, and put the kernel update on the next reboot train with a written exception. Write the exception with a date. Exceptions without dates are how 4.17-era code stays in production until someone names it. GBHackers already named it. Your change ticket can reuse the name.

For the people who only read the last section: grep RDS, patch to the Ubuntu versions Cyber Security News listed or your vendor’s equivalent, blacklist the modules where you do not need them, ignore the userns checkbox, and do not run the public PoC on a laptop that holds production keys. That is the whole Monday.