GhostLock Linux kernel flaw CVE-2026-43499 lets local attackers gain root on major distributions

Researchers published technical details and exploit code for GhostLock, a 15-year-old Linux kernel bug that can let a local attacker take full control of affected systems. Tracked as CVE-2026-43499, the use-after-free flaw was introduced in Linux 2.6.39 and affects major distributions since 2011; Nebula Security says it can be exploited for local privilege escalation to root and for container escape, and the bug was patched in April 2026.
Why it matters: Organizations and users running Linux systems should verify that April 2026 kernel fixes are installed, especially on shared systems and container hosts. Public exploit code raises the risk of copycat attacks because a local foothold could become full root access.

Sources

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
Ionut Arghire 2026.07.09 100% relevant
This article appears to be the establishing coverage of GhostLock as a named Linux kernel vulnerability with CVE-2026-43499, exploit code, affected-version history, and demonstrated root/container-escape impact.
← Back to all stories