| Researchers have disclosed GhostLock (CVE-2026-43499), a Linux kernel local privilege escalation vulnerability that has existed since 2011 in the rtmutex subsystem. The flaw leaves behind a dangling kernel pointer during proxy-lock rollback, creating a use-after-free condition that can be exploited to achieve root privileges and even container escape on unpatched systems. Researchers reported a highly reliable exploit and note that the bug requires no special kernel configuration or privileges to trigger. [link] [comments] |
Intelligence View
GhostLock (CVE-2026-43499): 15-year-old Linux kernel bug enables root and container escape
Researchers have disclosed GhostLock (CVE-2026-43499), a Linux kernel local privilege escalation vulnerability that has existed since 2011 in the rtmutex subsystem. The flaw leaves behind a dangling kernel pointer during proxy-lock…
SOCIAL SHARE CARD GENERATOR