15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
7 Articles
7 Articles
In the world of cybersecurity, researchers uncover long-standing vulnerabilities that could threaten modern operating systems. One such vulnerability is GhostLock, discovered by researchers at Nebula Security. Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that allows any logged-in user to gain full root control on an unpatched machine. The vulnerable code has been shipped by default in all m…
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek.
Cyber researchers sound alarm over a 15-year-old Linux kernel flaw – 'GhostLock' could let hackers seize unpatched machines in just five seconds
Researchers at Nebula Security have discovered a Linux kernel flaw dating back to 2011 that lets any logged-in user take full root control of an unpatched machine in just five seconds.Dubbed GhostLock (CVE-2026-43499), it was introduced in Linux 2.6.39 and fixed in Linux 7.1. The flaw allows an unprivileged local attacker to get a dangling kernel pointer to kernel stack memory with only regular threading syscalls, write a pointer to an arbitrary…
With a security message, the BSI warns against several highly dangerous vulnerabilities in the Linux kernel with a combined CVSS value of 8.6. The vulnerability allows remote, anonymous attackers, among other things, Denial-of-Service attacks. Oracle responds with the security advisory ELSA-2026-50372 and delivers an important kernel patch for Oracle Linux. The BSI security team, CERT, has pointed to multiple vulnerabilities in the Linux kernel …
15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions
A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed “GhostLock,” has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently affected major Linux distributions for over a decade. GhostLock originates from a logic error in the kernel’s real-time mutex (rtmutex) subsystem, introduced in Linux version 2.6.39 in 2011. The flaw remained undiscovered until it was patched in April 2…
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network
Coverage Details
Bias Distribution
- 100% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium







