Skip to content
New Exploit Targets Linux Kernel Use-After-Free Vulnerability

New Exploit Targets Linux Kernel Use-After-Free Vulnerability

First seen 14 Sep 2026, 10:47 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 11:21 UTC
  • CVE-2026-43499 allows disabling SELinux via a use-after-free exploit.
  • The 'ghost-hoock' exploit operates without root access, targeting user-space processes.
  • Multiple Linux kernel versions are affected, with no patches available for older versions like 4.19.

A new exploit targeting CVE-2026-43499, a use-after-free vulnerability in the Linux kernel's futex system, has been released. The exploit, named 'ghost-hoock', allows attackers to disable SELinux by manipulating the kernel's memory management. It is particularly effective on devices running vulnerable kernel versions, including Android devices like the Samsung Galaxy A17. The exploit requires no root access and operates entirely in user space, making it accessible to a wide range of attackers. The vulnerability affects multiple kernel versions, including 5.10, 5.15, 6.1, 6.6, 6.12, 6.18, and 7.0, while older versions like 4.19 are also at risk but lack patches. The exploit has been adapted for various kernel versions, including a specific adaptation for the 4.19 kernel. The first public proof-of-concept was released on July 15, 2026, indicating a growing threat landscape around this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-21
CVE-2026-43499 published
The vulnerability was officially disclosed, affecting multiple Linux kernel versions.
Sploitus
2026-07-15
First public PoC released
A proof-of-concept exploit for CVE-2026-43499 was made publicly available, demonstrating its potential impact.
Sploitus
Recent
Adaptations for 4.19 kernel
The exploit has been adapted for the 4.19 kernel, which lacks backported fixes, increasing risk for affected devices.
Sploitus

More articles in this cluster (2)

Following this threat?

Track Ghost-hoock and CVE-2026-43499 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed