15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Posted: Wed Jul 08, 2026 10:53 am
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.
Nebula turned it into a working root exploit that is 97% reliable in its testing and also escapes containers, and says Google awarded the team $92,337 through its kernelCTF bug-bounty program
Published Date: Jul 08, 2026
Vulnerabilities has been mentioned in this article.
CVE-2026-53166 CVE-2026-55200 CVE-2026-10702 CVE-2026-46242 CVE-2026-46817 CVE-2026-43499 CVE-2026-31431
More Information:
https://thehackernews.com/2026/07/15-ye ... -root.html
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.
Nebula turned it into a working root exploit that is 97% reliable in its testing and also escapes containers, and says Google awarded the team $92,337 through its kernelCTF bug-bounty program
Published Date: Jul 08, 2026
Vulnerabilities has been mentioned in this article.
CVE-2026-53166 CVE-2026-55200 CVE-2026-10702 CVE-2026-46242 CVE-2026-46817 CVE-2026-43499 CVE-2026-31431
More Information:
https://thehackernews.com/2026/07/15-ye ... -root.html