Researchers published technical details and exploit code for GhostLock, a 15-year-old Linux kernel bug that can let a local attacker take full control of affected systems. Tracked as CVE-2026-43499, the use-after-free flaw was introduced in Linux 2.6.39 and affects major distributions since 2011; Nebula Security says it can be exploited for local privilege escalation to root and for container escape, and the bug was patched in April 2026.
Why it matters: Organizations and users running Linux systems should verify that April 2026 kernel fixes are installed, especially on shared systems and container hosts. Public exploit code raises the risk of copycat attacks because a local foothold could become full root access.
Ionut Arghire
2026.07.09
100% relevant
This article appears to be the establishing coverage of GhostLock as a named Linux kernel vulnerability with CVE-2026-43499, exploit code, affected-version history, and demonstrated root/container-escape impact.
← Back to all stories