Critical GhostLock Vulnerability Allows Root Access on Linux Systems
Article Content
- •GhostLock (CVE-2026-43499) allows root access to any logged-in user on vulnerable Linux systems.
- •The vulnerability has existed undetected since 2011 and affects nearly all major Linux distributions.
- •A patch is available, but many systems remain vulnerable as updates are still being deployed.
A severe Linux kernel vulnerability, CVE-2026-43499, known as GhostLock, has been publicly disclosed by Nebula Security's VEGA team. This flaw, present since 2011, allows any logged-in user to gain full root control of affected systems in approximately five seconds, with no special permissions required. GhostLock affects nearly all mainstream Linux distributions, including Ubuntu, Debian, and Red Hat. The vulnerability exploits a logic error in the kernel's real-time mutex subsystem, specifically in the remove_waiter() function. A patch has been released, but many distributions are still vulnerable as updates are being rolled out. The flaw has been awarded a $92,337 bounty under Google's kernelCTF program due to its severity and the quality of the exploit. Organizations are urged to prioritize patching to mitigate risks associated with this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Vega, Debian and CVE-2026-10702 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…