Articles › Security Advisories

NebuSec Kernel LPE Batch, September 2026: CIQ Kernel Exposure Status

cvecve-2026-43042cve-2026-52923cve-2026-64560cve-2026-74597cve-2026-68376securitykernelrocky linuxltsnetworking

Stephen Simpson
Senior Customer Support Engineer

Sep 11, 2026

Introduction

In September 2026, NebuSec disclosed a batch of Linux kernel local privilege escalation flaws in a single oss-security report, most found through their automated exploit generation pipeline. ZcopyReaper (CVE-2026-43502) was the one they named publicly, and it has its own article since the check and mitigation are self-contained.

Engineering has completed triage across 22 CVEs tracked as part of this effort. 13 affect at least one currently maintained CIQ kernel line. The other 9 do not: 5 are deferred because the vulnerable configuration is not built into the affected CIQ kernels (the same situation as ZcopyReaper), and 4 are resolved or unreachable on every CIQ kernel line. Fixes are in progress across the 13 affected CVEs; status varies by CVE and by kernel line, see each section below.

This article covers 5 of the 13 in detail:

  • CVE-2026-43042 (MPLS label table race)
  • CVE-2026-52923 (SysV IPC IDR overflow)
  • CVE-2026-64560 (posix-cpu-timers exec race)
  • CVE-2026-74597 (ip6_tunnel ICMP error handling)
  • CVE-2026-68376 (SCTP auth_hmacs overflow)

The other 8 affected CVEs from this same triage effort are summarized at the end of this article. If you need more detail on one of those, or on any CVE from this disclosure not listed here, open a support case.

CVE-2026-43042: MPLS label table race

What it is: A race in the kernel's MPLS routing table (net/mpls/af_mpls.c). The lookup path (mpls_forward(), mpls_dump_routes()) reads the label table's size (net->mpls.platform_labels) and its backing array (net->mpls.platform_label) as an unsynchronized pair. A concurrent resize can let a lockless reader pair the new, larger size with the old, smaller array, producing an out-of-bounds access. Confirmed by the upstream/CentOS Stream 10 fix (commit 0f67d28f), which adds a seqcount around the resize path. An initial backport attempt broke kABI; a revised, kABI-safe version of the fix has since merged for most CIQ kernel branches (see Status below).

Severity: CVSS 7.1.

Exploit: Public exploit code exists as part of the NebuSec disclosure.

CIQ exposure: Built as a module across all 6 EL variants and all 4 CLK variants.

Status: Fix merged for RLC Pro 8, RLC Pro 10, LTS 8.6, LTS 9.2, and LTS 9.6. Still in progress for RLC Pro 9. The fix has been validated against the public exploit, with no reproduction after extended stress testing on the merged branches. Patched kernel versions: pending, will be added once released.

Interim mitigation: Until a released kernel with this fix is available for your variant, or if you do not run MPLS-based routing and prefer to block it regardless, you can block the module from loading:

sudo sh -c "printf 'install mpls_router /bin/false\n' > /etc/modprobe.d/block-CVE-2026-43042.conf"

⚠️ Confirm no production workload depends on MPLS routing before applying this. More likely to matter on telco and network-operator systems than general-purpose hosts.

CVE-2026-52923: SysV IPC IDR overflow

What it is: ipc_idr_alloc() in the SysV IPC checkpoint/restore path calls idr_alloc() without an upper bound. A crafted sequence can store a shared memory object in an out-of-range IDR slot; a later removal truncates the ID and frees the wrong slot, a use-after-free.

Severity: CVSS 7.8.

Exploit: Public exploit code exists, confirmed against a real RHEL 10 build (6.12.0-211.7.3.el10_2).

CIQ exposure: Core kernel code, built in with no isolating config option. Affects all 6 EL variants.

Status: Fixed for RLC Pro 8, RLC Pro 9, RLC Pro 10, and LTS 9.2. Still in progress for LTS 8.6 and LTS 9.6. Patched kernel versions: pending, will be added once confirmed.

Interim mitigation: SysV IPC is core kernel functionality, not a loadable module, so there is no "block the module" stopgap available for the branches still awaiting a fix.

CVE-2026-64560: posix-cpu-timers exec race

What it is: A race in posix_cpu_timer_del(), posix_cpu_timer_set(), and posix_cpu_timer_rearm() (kernel/time/posix-cpu-timers.c). A non-leader thread's exec() running concurrently with a timer operation can leave a timer attached to a freed thread-group-leader sighand, a use-after-free.

Severity: CVSS 7.8.

Exploit: Public PoC exists but targets Android/Pixel hardware.

CIQ exposure: Core kernel code, built in with no isolating config option. Affects LTS 9.2, LTS 9.6, RLC Pro 9, and RLC Pro 10. LTS 8.6 and RLC Pro 8 are not affected.

Status: Fixed for RLC Pro 9 and RLC Pro 10. Still in progress for LTS 9.2 and LTS 9.6. Upstream mainline fix exists (commit 920f893f735e). Patched kernel versions: pending, will be added once confirmed.

Interim mitigation: This is core process/signal handling, not something that can be disabled without breaking the system.

CVE-2026-74597: ip6_tunnel ICMP error handling

Note: unlike the other four CVEs in this article, this one has a remote attack vector, not local privilege escalation. Treat it as a different threat model.

What it is: ip6ip6_err() mishandles a crafted IPv6 ICMP error packet containing a malformed inner destination-options header, corrupting skb->cb[] (out-of-bounds write). Engineering characterizes real-world impact as denial-of-service rather than a clean escalation path.

Severity: CVSS 7.0.

Exploit: No public proof-of-concept found as of this writing.

CIQ exposure: Built as a module requiring an IPv6 tunnel interface to be configured. Affects all 6 EL variants.

CVE-2026-43037 is a separate, unrelated CVE that also involves ip6_tunnel. Do not confuse the two, see Mitigating CVE-2026-43037 (ip6_tunnel).

Status: No fix available yet. A fix is in final review across all 6 EL variants and expected soon.

Interim mitigation: None identified. Watch this article for an update once a patched kernel ships.

CVE-2026-68376: SCTP auth_hmacs overflow

What it is: The auth_hmacs array in struct sctp_cookie is undersized. Configuring four HMAC identifiers during SCTP association init overflows into the adjacent auth_chunks field, corrupting it and allowing an invalid HMAC ID to be accepted, which triggers an out-of-bounds read in sctp_auth_get_hmac().

Severity: CVSS 8.1 (CIQ's assessment; some public trackers list lower scores for this CVE).

Exploit: No public proof-of-concept found as of this writing.

CIQ exposure: Built as a loadable module, the vulnerable array is written directly from network-supplied data. Affects all 6 EL variants.

Status: No fix available yet. A fix is in final review across all 6 EL variants and expected soon.

Interim mitigation: Not yet determined. If SCTP is confirmed as not loaded by default on CIQ kernels, a modprobe block similar to the MPLS mitigation above may be viable for hosts that cannot wait for the fix, but this has not been evaluated.

Other CVEs in this batch

The other 8 CVEs from this same triage effort also affect at least one CIQ kernel line. Status varies by CVE, most do not have a released fix yet either:

  • CVE-2026-74480 (bridge multicast, CVSS 7.8): fix in final review across all 6 EL variants.
  • CVE-2026-74581 (ipv6 fib6 rules, CVSS 7.8): fixed for RLC Pro 9, LTS 9.2, and LTS 9.6; still in review for LTS 8.6, RLC Pro 8, and RLC Pro 10.
  • CVE-2026-31678 (openvswitch, CVSS 7.8): fix in final review across all 6 EL variants.
  • CVE-2026-72255 (nf_queue bridge, CVSS 7.8): fix in final review across all 6 EL variants.
  • CVE-2026-52912 (nf_queue bridge, CVSS 7.8): fixed for RLC Pro 10; still in review for the other 5 EL variants.
  • CVE-2026-52924 (SCTP cookie handling, CVSS 9.8): not yet started; affects LTS 8.6, LTS 9.2, LTS 9.6, and RLC Pro 10.
  • CVE-2026-52929 (SCTP stream handling, CVSS 7.5): not yet started; affects all 6 EL variants.
  • CVE-2026-23274 (xt_IDLETIMER, CVSS 7.8): not yet started; affects LTS 8.6 and RLC Pro 8 only.

None of these 8 have a full write-up in this article yet. Open a support case if you need more detail on any of them.

Notes

  • CVSS figures above reflect CIQ's own severity assessment. Public trackers (Red Hat, CVE.org, and other aggregators) show different numbers for three of the five CVEs covered here, in one case (CVE-2026-68376) by a wide margin. Where they conflict, this article uses CIQ's internal figure.
  • Only CVE-2026-52923 has a confirmed public exploit against a CIQ-relevant kernel build. The others either have no confirmed public PoC (74597, 68376) or a PoC against a non-CIQ platform (64560 on Android, 43042 within the general NebuSec batch).
  • This article will be updated as fixes ship and confirmed patched kernel versions become available, for the 5 CVEs covered in detail above and for the 8 summarized in Other CVEs in This Batch.

oss-security disclosure
Mitigating ZcopyReaper (CVE-2026-43502)
Mitigating CVE-2026-43037 (ip6_tunnel)
CVE-2026-43042 (NVD)
CVE-2026-43042 (MITRE)
CVE-2026-52923 (NVD)
CVE-2026-52923 (MITRE)
CVE-2026-64560 (NVD)
CVE-2026-64560 (MITRE)
CVE-2026-74597 (NVD)
CVE-2026-74597 (MITRE)
CVE-2026-68376 (NVD)
CVE-2026-68376 (MITRE)
Rocky Linux Errata