CVE Tools

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

The Hacker NewsBy The Hacker News

PoC public

Our summary

Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a long-standing Linux kernel flaw (present since 2011) that allows a logged-in user on unpatched systems to gain full root privileges and break out of containers. The issue is triggered via ordinary local threading behavior with no special permissions or network access, making it a serious risk for multi-tenant hosts, cloud instances, CI runners, and shared environments. Nebula published working exploit code, underscoring the urgency of applying the latest kernel updates from affected distributions.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store