// NEXUSVOID CYBER NEWS

<- ALL CYBER NEWS

High

GhostLock, CVE-2026-43499, Linux kernel, privilege escalation, container escape, root

A 15-Year-Old Linux Bug Turns Any Logged-In User Into Root

GhostLock, CVE-2026-43499, is a 15-year-old Linux kernel flaw that lets any authenticated user seize full root and break out of containers on most distributions. A bug this old and this broad rewards patience from defenders and attackers alike.

Researchers at Nebula Security have disclosed GhostLock, tracked as CVE-2026-43499, a fifteen-year-old flaw in the Linux kernel that lets any logged-in user take full root control of an unpatched machine, as reported by The Hacker News. Because the vulnerable code has lived in the kernel for so long, it affects most Linux distributions in use today.

On its own, a local privilege escalation needs an attacker to already have some access, which is why these bugs are sometimes underrated. In practice they are the second half of almost every intrusion. A phished credential, a web shell, or a compromised container gets a foothold, and a flaw like GhostLock turns that foothold into complete control of the host.

The container escape angle is what makes this one worth attention in cloud and multi-tenant environments. If a single container can be used to reach root on the underlying host, the isolation that shared infrastructure depends on stops holding, and one compromised workload becomes a path to its neighbors.

Patching the kernel across affected fleets is the direct fix, and it is worth treating the age of this bug as the lesson. Code that has sat untouched and trusted for fifteen years is not proven safe by its age, it is simply unexamined, and the same continuous verification applied to new code belongs on the old foundations underneath it.

Sources: The Hacker News; Nebula Security.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.