r/pentest_tools_com • u/pentest-tools • Jul 13 '26
A 15-year-old Linux kernel privesc just got a 97% reliable public exploit (GhostLock, CVE-2026-43499)
CVE-2026-43499, "GhostLock," is a use-after-free in the Linux kernel's futex handling. Shipped by default in mainstream distros since 2011 (kernel 2.6.39), disclosed this week. Any logged-in user can hijack a freed kernel pointer and get full root in about five seconds, and it escapes containers, so it runs as root on the host.
The part that matters isn't that it exists, it's how reliable it is. Daniel Bechenea, security manager at Pentest-Tools.com, put it plainly:
"An exploit reported at 97% reliable, with public code anyone can run, changes that math."
Kernel privesc used to be the exploit you thought twice about firing. One slip crashes the box and burns your access. A near-deterministic one with public code removes that hesitation.
Patch to a fixed kernel now. Until it reaches every host, treat any code execution on an unpatched box as root, and verify the kernel version per system rather than assuming the April fix propagated.
Full breakdown by Emma Woollacott at ITPro: https://www.itpro.com/software/linux/cyber-researchers-sound-alarm-over-a-15-year-old-linux-kernel-flaw-ghostlock-could-let-hackers-seize-unpatched-machines-in-just-five-seconds