LIVE · cybersecurity feed
Live wire
CVE-2026-43499critical

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Nebula Security has revealed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present for 15 years. This flaw allows any logged-in user to achieve root privileges and container escape on unpatched systems, as it is included by default in most Linux distributions.

zeroday.news · 24d ago

A Linux kernel vulnerability, present for 15 years and now publicly disclosed as CVE-2026-43499, has been identified by Nebula Security. This flaw, dubbed GhostLock, allows any authenticated user on an unpatched system to escalate their privileges to root and to break out of containerized environments.

The vulnerability is a significant concern because it has been a part of the Linux kernel for approximately 15 years. Due to its long-standing presence, it is included by default in the majority of Linux distributions currently in use. This widespread inclusion means that a large number of systems are potentially susceptible to exploitation if they have not been updated with the latest security patches.

GhostLock's impact is twofold. Firstly, it enables privilege escalation, meaning a user with standard access can gain administrative (root) privileges. This level of access allows an attacker to modify system files, install malicious software, and gain complete control over the affected machine.

Secondly, the vulnerability facilitates container escape. Containers, such as those used by Docker and Kubernetes, are designed to isolate applications and their dependencies from the host system and from each other. A successful container escape would allow an attacker to move from within a compromised container to the underlying host operating system, potentially compromising other containers or the entire infrastructure.

The researchers at Nebula Security have highlighted that the vulnerability is present in the kernel and affects most Linux distributions. This implies that the fix will likely involve kernel updates provided by individual distribution vendors.

Details regarding the specific technical mechanisms exploited by GhostLock have not yet been fully elaborated upon in the initial disclosure. However, the severity of the vulnerability is underscored by its ability to grant root access and enable container escapes, two of the most critical security outcomes an attacker would seek.

Given the widespread nature of the vulnerability and its long history, it is crucial for system administrators to prioritize patching their Linux systems. Without timely updates, these systems remain exposed to potential attacks that could lead to significant data breaches and system compromises.

Users and administrators are advised to consult their respective Linux distribution's security advisories and apply any available kernel updates as soon as possible. While specific mitigation steps beyond patching are not detailed, maintaining updated systems is a fundamental security practice that directly addresses this newly disclosed threat.

linuxkernelvulnerabilityprivilege escalationcontainer escape
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]