GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years

·Hacker News··

GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.

Read full article →

Related Articles

Xiaomi: New CPU matches Apple cores single threaded, much faster multithreaded
tosh · Hacker News · 11h ago
MS Paint and Photos inivisibly watermark even locally generated output with GUID
ComputerGuru · Hacker News · 11h ago
IPFS Maintainers Winding Down
iand · Hacker News · 10h ago
LLMs could control their host machines by exploiting inference engines
zdw · Hacker News · 7h ago
Show HN: GlassBox – what the browser reveals, and how identifiable you are
tke248 · Hacker News · 10h ago