---
schema: 1
kind: vulnerability
title: "GhostLock (CVE-2026-43499) — Linux kernel rtmutex use-after-free with a public, 97%-reliable root and container-escape exploit"
headline: "GhostLock (CVE-2026-43499): 15-year-old Linux rtmutex UAF gets a public 97%-reliable root + container-escape exploit"
summary: >
  GhostLock is a use-after-free in the Linux kernel's rtmutex priority-inheritance code, present since 2.6.39 (2011) and reachable on any kernel built with the default CONFIG_FUTEX_PI. Nebula Security published a working exploit on 7 July achieving root in ~5 seconds at 97% reliability and escaping containers to the host. Fixed upstream in April 2026 — confirm the running kernel carries the fix, not just "a recent kernel."
discovered_at: "2026-07-08T20:35:00Z"
event_date: 2026-07-07
run_id: 2026-07-08T2009Z-intel
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - priv-esc
  - poc-public
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - technology
entities: []
techniques: [T1068, T1611]
cves:
  - id: CVE-2026-43499
    cvss: null
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - poc-public
      - patch-available
    affected: "Linux kernel 2.6.39 → pre-fix builds with CONFIG_FUTEX_PI=y"
    fixed: "commit 3bfdc63936dd (fixed 2026-04-20, backported 2026-05-04)"
sources:
  - url: "https://nebusec.ai/research/ionstack-part-2/"
    publisher: "Nebula Security"
    date: "2026-07-07"
    role: primary
  - url: "https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html"
    publisher: "The Hacker News"
    date: "2026-07-08"
    role: corroborating
closed_sources: []
evidence:
  - quote: "GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by Nebu that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege."
    publisher: "Nebula Security"
  - quote: "No one is known to be exploiting it in the wild, but Nebula has published working exploit code, so anyone can now run it."
    publisher: "The Hacker News"
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: true
deep_dive_category: linux-lpe
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Confirm the running kernel includes commit 3bfdc63936dd (backported 2026-05-04) — a build date of 'recent' is not sufficient; verify the specific fix on every multi-tenant, CI/CD and container-host Linux fleet."
  - "Where immediate patching is not possible, enable CONFIG_RANDOMIZE_KSTACK_OFFSET and CONFIG_STATIC_USERMODE_HELPER to raise exploit cost (not a fix), and prioritise hosts where untrusted local code runs (shared build runners, container platforms)."
updates:
  - at: "2026-09-29T23:35:26Z"
    run_id: 2026-09-29T2134Z-audit
    type: improvement
    internal: true
    summary: >
      Nebula Security's post now credits "Nebu" where it credited its tool VEGA, and no longer names
      VEGA. The evidence quotation follows the current text, and the analysis cites The Hacker News,
      which still names VEGA, for the tool. No finding changed. The entry also gains the ATT&CK
      mapping its analysis already described (privilege escalation through a kernel flaw, escape to
      host) and an Admiralty rating of B2: original research by the discovering firm, confirmed by the
      upstream fix.
    fields: [evidence, techniques, classification, body]
migrated_from: null
---

GhostLock (CVE-2026-43499) is a stack use-after-free in the Linux kernel's rtmutex priority-inheritance code, discovered by Nebula Security ([Nebula Security, 2026-07-07](https://nebusec.ai/research/ionstack-part-2/)) with its automated bug-hunting tool VEGA ([The Hacker News, 2026-07-08](https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html)). The defect lives in `remove_waiter()` (kernel/locking/rtmutex.c): the helper unconditionally clears `current->pi_blocked_on`, an assumption valid on the normal self-blocking path but broken on the proxy-lock rollback path — `rt_mutex_start_proxy_lock()` can enqueue (and, on `-EDEADLK`, roll back via `remove_waiter()`) a waiter on behalf of a *different* task, so the helper scrubs the wrong task's state and leaves a dangling pointer into an already-freed kernel stack frame. The only prerequisite is `CONFIG_FUTEX_PI=y`, the default on essentially every mainstream distribution — no special capability, user namespace, or unusual configuration, so any unprivileged local user is in scope.

The flaw was introduced in Linux 2.6.39 (commit 8161239a8bcc, a 2011 rtmutex PI-algorithm rework) and shipped for over fifteen years until it was reported to security@kernel.org on 18 April 2026, fixed two days later in commit 3bfdc63936dd, and backported by 4 May 2026 — meaning most currently-maintained kernels already carry the fix, but any distribution build not rebased onto a post-April-2026 source tree remains exposed. Nebula turned the primitive into a full exploit: reclaim the freed stack frame, use a `prefetch`-based side channel plus the DirtyMode `/proc/sys` write-what-where technique to hijack a function pointer, and reach root in roughly five seconds at 97% reliability in testing; the same primitive escapes containers, letting a compromised container break out to the host kernel. Google awarded $92,337 through kernelCTF, and Nebula published full exploit source alongside the write-up on 7 July — no in-the-wild exploitation is reported, but public working code against a 15-year exposure window makes this a same-week verification item ([The Hacker News, 2026-07-08](https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html)).

Kill chain and detection: the exploit is a local privilege-escalation and container-escape primitive — `T1068 Exploitation for Privilege Escalation`, with the container-escape variant also mapping to `T1611 Escape to Host`. Because the trigger is a legitimate futex-PI syscall pattern, there is no clean single syscall signature; hunt instead for the downstream effects — unexpected `uid=0` transitions from processes with no setuid provenance, kernel oops/`BUG: KASAN`/`general protection fault` entries referencing `rtmutex`/`remove_waiter` in `dmesg` on hosts running untrusted code, and, on container platforms, a container process acquiring host-level capabilities or writing under host `/proc/sys`. Hardening short of the kernel patch: `CONFIG_RANDOMIZE_KSTACK_OFFSET` defeats the specific stack-reuse step (turning a deterministic overlap into roughly a 1-in-32 guess) and `CONFIG_STATIC_USERMODE_HELPER` closes the specific DirtyMode write-what-where path this PoC relied on — both raise cost but are not fixes. The durable remediation is confirming the running kernel includes commit 3bfdc63936dd, with priority on multi-tenant, shared-CI-runner and container-host fleets across Swiss/EU public-sector and cloud/Kubernetes estates where untrusted local code is most likely to run.
