Page 1 of 1

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Posted: Wed Jul 08, 2026 10:53 am
by Starburst-David
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.

The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.

Nebula turned it into a working root exploit that is 97% reliable in its testing and also escapes containers, and says Google awarded the team $92,337 through its kernelCTF bug-bounty program

Published Date: Jul 08, 2026

Vulnerabilities has been mentioned in this article.
CVE-2026-53166 CVE-2026-55200 CVE-2026-10702 CVE-2026-46242 CVE-2026-46817 CVE-2026-43499 CVE-2026-31431

More Information:
https://thehackernews.com/2026/07/15-ye ... -root.html