type: cve ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [cve, zero-day, kev] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, finance, healthcare, energy] ยท au_impact: true
GhostLock (CVE-2026-43499)
GhostLock is a 15-year-old Linux kernel vulnerability disclosed by Nebula Security that enables any logged-in user to gain full root access and escape containers with 97% reliability in testing. It is present in virtually every mainstream Linux distribution since 2011.
Details
| Field | Value |
|---|---|
| CVE | CVE-2026-43499 |
| Discovered by | Nebula Security |
| Type | Linux kernel privilege escalation + container escape |
| Age | ~15 years (present since at least 2011) |
| Scope | Virtually all mainstream Linux distributions |
| Impact | Any logged-in user โ full root โ container escape |
| Exploit | Working exploit code published; no in-the-wild exploitation confirmed |
| Bounty | $92,337 from Google kernelCTF programme |
Affected Systems
- Nearly every mainstream Linux distribution since 2011
- Cloud workloads, containers, virtual machines
- IoT / embedded Linux devices
Exploitation Status
- Proof-of-concept exploit published: Yes
- In-the-wild exploitation: Not confirmed at time of disclosure
- CISA KEV status: Not yet added (as of Jul 9)
Australian Significance
Given the widespread use of Linux in Australian critical infrastructure, cloud services, and government systems, this vulnerability has significant Au Impact across sectors. Acsc advisories should be monitored for guidance. (raw/digests/Cyber-Digest-2026-07-09)
Related Pages
- Fortibleed โ Another critical infrastructure vulnerability (Fortinet devices)
- Rogue Agent Dialogflow โ Cloud platform vulnerability
- Acsc Cms Exploitation โ Active exploitation campaign affecting AU systems