15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
CVE-2026-43499 (GhostLock) exposes a 15-year-old Linux kernel locking flaw enabling any local user to achieve root and escape containers—affecting virtually every mainstream distribution since 2011 and demanding immediate patching.
Summary written by editorial AI · Source link below
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network
Editorial Analysis
Nearly universal Linux distribution exposure combined with local-to-root escalation and container escape makes this one of the most impactful kernel vulnerabilities in recent years.
Initiate emergency patching of all Linux hosts and container infrastructure for CVE-2026-43499 and validate remediation within 72 hours.
A newly disclosed 15-year-old Linux kernel vulnerability allows full system takeover and container escape, requiring immediate enterprise-wide patching.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Vulnerabilities Desk
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More20 Jul
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.20 Jul
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen20 Jul
- [NEU] [hoch] Grafana: Schwachstelle ermöglicht Manipulation von Dateien20 Jul
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen20 Jul