Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-43499 [High]

Curated 2 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-43499.

Vendor
Linux
Product
Linux kernel
Affected versions
Linux kernel v2.6.39-rc1 through versions before v7.1-rc1; fixed in Linux 7.1
Coverage Span
2026-07-07 → 2026-07-15
Reports
2 related reports

Associated Reports & Timeline

1.
nebusec.ai | vulnerability | High | | original ↗ | #public-poc | #featured | #vulnerability-research | #container-security
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by Nebula Security that exists in every major distribution since 2011. After turning it into a stable privilege escalation and container escape, we took one step further and used GhostLock to develop the world's first public Android 17 root. This writeup covers the additional exploit techniques used to migrate the exploit for Android.
2.
GhostLock (CVE-2026-43499) is a Linux kernel stack use-after-free present since 2011. NebuSec turned it into a reliable local privilege-escalation and container-escape exploit; the issue is fixed in Linux 7.1.
Why it matters: A 15-year-old Linux kernel stack use-after-free was turned into reliable local privilege escalation and container escape, affecting essentially every unpatched major distribution.