The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Saturday, July 11, 2026 WIRED
Security!

AI Uncovers 15-Year-Old Linux Kernel Privilege-Escalation Flaw

Nebula Security's AI-driven bug-hunting tool VEGA discovered GhostLock (CVE-2026-43499), a use-after-free vulnerability lurking in the Linux kernel since 2011.

WIRED — The flaw grants any logged-in user root access on unpatched systems without special permissions. It affects all major distributions; Ubuntu 24.04, 22.04, and 20.04 LTS remain vulnerable. Patch coverage is uneven.

The GhostLock vulnerability, identified as CVE-2026-43499, was discovered by the team at Nebula Security using their AI-powered bug-hunting tool, VEGA. The security flaw is a use-after-free vulnerability that had existed within the Linux kernel since 2011, remaining undetected by humans for over a decade.

Exploiting this flaw allows any user with basic login credentials to elevate their privileges to root level, granting full administrative control over the system. The vulnerability is widespread, affecting all major Linux distributions. Specifically, Ubuntu LTS versions 20.04, 22.04, and 24.04 are still susceptible to the attack.

In recognition of the discovery and its potential impact, Google awarded the researchers a bounty of $92,000. While patches are being deployed, the current state of coverage across different environments is inconsistent.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

◀ Briefs — Page D1

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy