GhostLock (CVE-2026-43499): 15-Year Linux Kernel Use-After-Free Yields Root and Container Escape — 97%-Reliable Public PoC Released
Nebula Security's VEGA team disclosed GhostLock, a use-after-free in the Linux kernel's rtmutex/futex priority-inheritance subsystem present in every mainstream distribution since 2011 (kernels 2.6.39 through 7.1). The flaw requires no special privileges, kernel capabilities, or network access — ordinary threading calls suffice — and the researchers have released a working exploit with a 97% success rate that also achieves container escape, breaking tenant isolation on shared Kubernetes nodes and CI/CD runners. Patch availability remains uneven: Ubuntu 24.04, 22.04, and 20.04 LTS were still listed as in-progress as of early July, and the initial upstream fix introduced a secondary null-pointer crash (CVE-2026-53166) requiring a follow-up patch, meaning defenders must verify they hold the final corrected build.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.