Researchers at Nebula Security have identified Ghostlock, a Linux kernel vulnerability tracked as CVE-2026-43499 that has existed since Linux 2.6.39 in 2011.
This flaw allows attackers with local access to escalate privileges to root on almost all major Linux distributions released since that time. Linux kernel version 7.1 includes a fix for the problem, but currently, the only practical precaution is to install an updated kernel.
The vulnerability was discovered by Nebula Security’s AI agent Vega, and Google provided a bug bounty of $92,337 through its KernelCTF program. During testing, the exploit worked successfully 97 percent of the time.
What does Ghostlock do and which Linux systems are affected
Ghostlock is a local privilege escalation vulnerability that allows an attacker with access to the system to potentially gain full root privileges and take full control.
The flaw stems from a helper function within the Linux kernel’s scheduling system, which is responsible for cleaning up tasks after they have finished. When a deadlock occurs and rollback is initiated, the function can free the memory while another function still holds a reference to it. This situation creates a use-after-free condition that attackers can exploit.
This vulnerability is present in Linux kernel versions 2.6.39 through Linux 7.0, released in 2011, and affects almost all major Linux distributions released since 2011. It affects both server and desktop Linux systems, particularly those where an attacker has already established some level of local access.
Given its 15-year history, Ghostlock has been a persistent issue, affecting the majority of Linux systems deployed worldwide over that period.
Why only a patched kernel fixes this and what should users do
There is currently no practical solution or mitigation for Ghostlock. Nebula Security has stated that the only reliable solution is to install a patched kernel.
Users and administrators of affected systems should verify their current kernel version by running uname -r on the affected device, then update to Linux 7.1 or newer through the distribution’s standard package management system.
After updating, a system reboot is required to activate the new kernel, and you should verify that the update was successful by checking uname -r again after the reboot.
For enterprise Linux distributions such as Red Hat Enterprise Linux, SUSE Linux Enterprise, and Ubuntu LTS, vendors are expected to backport fixes to their supported versions. Users of these distributions should remain alert for kernel updates through their normal update channels.
For distributions that use the mainline kernel directly, installing a kernel from the 7.1 series or later will resolve the issue.
GhostLock requires local access to exploit, which acts as a mitigation factor. An attacker must first gain some level of access to the system before using GhostLock to escalate privileges.
Common methods of gaining initial access include compromised user accounts through phishing or credential theft, user-installed malicious software, systems shared with multiple users, exploiting other vulnerabilities that allow code execution, or physical access to unattended devices.
Because GhostLock has a 97 percent success rate, once an attacker has any kind of local access, the tool provides an almost certain path to root privileges.
How AI helped in finding Ghostlock and where the solution is available
Vega, an AI bug-hunting and security agent developed by Nebula Security, exposed a flaw. Nebula says VEGA can identify vulnerabilities more quickly than human researchers.
This finding highlights broader changes in vulnerability research. Other recent examples include Anthropic’s Mythos model, which found vulnerabilities in highly sensitive US government systems during a testing exercise in June 2026.
Senator Mark Warner reported that National Security Agency head Joshua Rudd said that Mythos “broke into almost all of our classified systems, not in weeks, but in hours.”
The pattern shows that AI-assisted vulnerability discovery is becoming an important part of both defensive and offensive security efforts. Older code that hasn’t been examined for years, such as the 15-year-old function behind GhostLock, is likely to receive renewed attention as AI tools become more capable.
For Linux system administrators, it is recommended to prioritize kernel updates on production systems, especially on systems with multiple users or shared access:
- Verify that the update paths are available through the current distribution’s package management system.
- Review recent activity on affected systems for signs of prior exploitation.
- Consider whether local account access controls need to be tightened.
For desktop Linux users, update to the latest kernel version available through the distribution’s standard update mechanism:
- Reboot after installing the kernel update to activate the new version.
- Be aware that some distributions delay major kernel version changes; Verify that the specific fix has been backported into the installed kernel.
For cloud infrastructure users, verify that the provider images have been updated to include the patched kernel:
- Rebuild virtual machines from updated base images if necessary.
- Consider running a vulnerability scan against production systems to identify any unpatched balances.
The Nebula security disclosure and Google’s acceptance of the KernelCTF program provide reference details that security teams can use to verify their systems. The simplest way to confirm whether Ghostlock has been addressed is to check the kernel version.
Additionally, local privilege escalation detection methods, such as endpoint monitoring, audit logs, and behavioral analysis, are the primary tools for identifying potential exploits.
Ghostlock is part of an expanding list of long-standing Linux kernel vulnerabilities discovered in recent years. Older code developed before modern security review practices often contains subtle bugs that may only surface years later. The combination of AI-assisted searches and the extensive Linux kernel code base suggests that more similar findings are likely.
Linus Torvalds recently expressed frustration over AI-generated bug reports, particularly those that highlight kernel security issues without providing clear exploit paths.
In contrast, Ghostlock is different: it includes a working exploit, a high success rate, and a significant reward, supporting the validity of the discovery.
Linux 7.1 with the Ghostlock patch is now available through mainline kernel repositories, distribution package management systems for those that have incorporated the fix, and updated cloud images from major infrastructure providers. Users should install updates as soon as their distribution introduces a new kernel version, as there is no interim mitigation available while they wait.





