threat-intel
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
High
Summary
Researchers at Nebula Security discovered GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows an unprivileged user to gain root access on a machine. The flaw, discovered by their AI-driven bug-hunting tool VEGA, has been present in mainstream Linux distributions since 2011 and has been exploited in a chain with a Firefox vulnerability (IonStack) to achieve remote root access. While no active exploitation is currently known, the researchers have released exploit code, highlighting the ongoing risk and the need for immediate patching.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
