GhostLock (CVE-2026-43499): 15-year-old Linux kernel flaw enables root and container escape (thecybersecguru.com)
from UnLocoPoco@lemmy.world to cybersecurity@infosec.pub on 09 Jul 07:04
https://lemmy.world/post/49215806

Researchers have disclosed GhostLock (CVE-2026-43499), a Linux kernel local privilege escalation vulnerability in the rtmutex subsystem that reportedly dates back to 2011. The flaw stems from a use-after-free condition caused by a dangling pointer during proxy-lock rollback and can be leveraged for root privilege escalation and container escape on vulnerable systems.

#cybersecurity

threaded - newest

poinck@lemmy.world on 10 Jul 18:09 collapse

Already solved in linux-6.12.86-1 (debian stable)

security-tracker.debian.org/…/CVE-2026-43499