daily cyber × ai intelligence

index

tagged

[CVE-2026-43499]

2 editions · 2 items

July 9, 2026

  • GhostLock (CVE-2026-43499), disclosed by Nebula Security, is a 15-year-old Linux kernel stack use-after-free that lets any logged-in user gain full root and escape containers on unpatched systems — no special permissions, settings, or network access required. It ships as "IonStack part II," the kernel half of a full browser-to-kernel chain that pairs a Firefox 0-day (pre-151.0.2) with the kernel bug for a click-to-compromise Android 17 root demo. nebusec.ai, The Hacker News · Vulnerabilities & Exploits

in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro