CVE-2026-43499: GhostLock, Yet Another Linux LPE/Container Escape

Last Updated: 2026-07-09T20:49:44Z

CVSSv3: 7.8

What’s Happening

Nebula Security has disclosed “GhostLock,” another Linux kernel exploit leading to local privilege escalation and container escape. This one was found by their VEGA vuln research AI model.

GhostLock affects Linux kernel versions from 2.6.39 to 7.1. Patches are being backported by distributions.

This vulnerability is the second part of a two-part attack chain which Nebula calls “IonStack.” The first part was CVE-2026-10702, a Firefox sandbox escape. SentinelOne has a good explainer.

Taken together, the IonStack chain could lead to a rooted device from visiting a malicious website.

A full PoC of the attack chain has been released by NebuSec.

Actions

Patch systems with patches available. See below for distribution advisories. There does not appear to be an alternative mitigation, as there was with CopyFail/DirtyFrag.

Distribution Patch Notes

1 Like