Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [cve, zero-day, kev] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, finance, healthcare, energy] ยท au_impact: true

GhostLock (CVE-2026-43499)

GhostLock is a 15-year-old Linux kernel vulnerability disclosed by Nebula Security that enables any logged-in user to gain full root access and escape containers with 97% reliability in testing. It is present in virtually every mainstream Linux distribution since 2011.

Details

Field Value
CVE CVE-2026-43499
Discovered by Nebula Security
Type Linux kernel privilege escalation + container escape
Age ~15 years (present since at least 2011)
Scope Virtually all mainstream Linux distributions
Impact Any logged-in user โ†’ full root โ†’ container escape
Exploit Working exploit code published; no in-the-wild exploitation confirmed
Bounty $92,337 from Google kernelCTF programme

Affected Systems

  • Nearly every mainstream Linux distribution since 2011
  • Cloud workloads, containers, virtual machines
  • IoT / embedded Linux devices

Exploitation Status

  • Proof-of-concept exploit published: Yes
  • In-the-wild exploitation: Not confirmed at time of disclosure
  • CISA KEV status: Not yet added (as of Jul 9)

Australian Significance

Given the widespread use of Linux in Australian critical infrastructure, cloud services, and government systems, this vulnerability has significant Au Impact across sectors. Acsc advisories should be monitored for guidance. (raw/digests/Cyber-Digest-2026-07-09)

Related Pages