GhostLock ( CVE -2026-43499 ) is a critical vulnerability in the Linux kernel that has been hidden for 15 years — since 2011 — and allows any logged-in user to gain full root access to unpatched systems. The discovery was made by researchers at Nebula Security , who also developed a working exploit with 97% reliability in tests, even being able to escape containers . Google rewarded the team with $92,337 through the kernelCTF bug-bounty program .
See also: Copy Fail: Linux vulnerability allows root access to systems

GhostLock affects almost every mainstream Linux released since 2011, as the vulnerable code is included by default. What’s particularly worrying is that the exploit doesn’t require any special permissions, unusual settings, or network access — simple threading from any local program are sufficient. In Nebula Security, the process of gaining root accesstook just five seconds.
Although no attacks have yet been recorded in practice, the publication of exploit code by Nebula Security makes the immediate application of available patches an imperative for every system administrator.
How GhostLock works technically
The Linux kernel has a priority system that prevents urgent tasks from being blocked by unimportant ones. This system includes a cleanup step that is performed as soon as a task is no longer waiting. In the rare case where a lock operation fails and needs to be undone, the cleanup may occur at the wrong time, resulting in the wrong task's record being deleted.
This bug leaves the kernel with a "pointer" that points to a memory location that has already been freed and reused. Relying on this stale pointer is a use-after-free vulnerability. The Nebula Security team was able to exploit this small bug to gain complete control, tricking the kernel into executing their own code as the root user . The GhostLock vulnerability is rated 7.8 out of 10 (high, not critical), as the attacker would already need to have local access to the system.
The discovery was made with the help of VEGA, an artificial intelligence-based bug hunting tool developed by Nebula Security. It highlights the growing role of AI in discovering vulnerabilities that have remained unseen for years in heavily used code.
GhostLock and the IonStack chain: Danger from browser to root
GhostLock isn't just an isolated vulnerability — it's part of an attack chain that Nebula Security calls IonStack . The first link in the chain is CVE-2026-10702 , a vulnerability in Firefox that allows code execution within the browser and escape from its sandbox . GhostLock completes the chain by allowing privilege escalation to root .
See also: CVE-2026-23111: A character in the Linux kernel allows root access

Nebula Security has demonstrated the full IonStack chain against Firefox on Android — from a single click on a malicious link to full control of the device. This highlights the importance of a “local-only” kernel vulnerability: while it requires local access on its own, when combined with a browser exploit it can lead to a full remote compromise. The company plans to publish a full analysis of the Android exploit .
GhostLock isn't the only privilege escalation vulnerability to be discovered this year. Earlier this year, researchers uncovered Bad Epoll ( CVE-2026-46242 ), which also allows an unprivileged user to gain root access and — unusually for this type of vulnerability — also works on Android . In addition, Copy Fail ( CVE-2026-31431 ) is already on CISA 's list of vulnerabilities that are being exploited in real attacks.
How to protect yourself from GhostLock
The vulnerability was patched in April with patch 3bfdc63936dd , and Linux distributions are already rolling out updates. However, there is an important detail: the initial fix introduced a separate crash bug ( CVE-2026-53166 ), and the final version of the fix was still being finalized in early July. Therefore, administrators should install the current kernel of their distribution, and not just the first patched version.
There is no complete workaround , as the operations that trigger the vulnerability are routine for any local process. Two compile-time options — RANDOMIZE_KSTACK_OFFSET and STATIC_USERMODE_HELPER — can make exploitation more difficult, but are mitigations, not fixes. Priority should be given to shared and multi-tenant systems, including cloud servers , containers , and CI runners , where an attacker has a higher chance of gaining the initial local access required by the vulnerability.

See also: 9-year-old Linux Kernel vulnerability allows root access
GhostLock is a reminder that even the most mature and tested code can hide serious vulnerabilities for decades. Automated analysis with AI tools like VEGA is changing the game in vulnerability discovery, but it also speeds up the time organizations have to respond. Prompt application of security updates remains the only effective defense against GhostLock .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
