AI Uncovers 15-Year-Old Linux Kernel Privilege-Escalation Flaw
Nebula Security's AI-driven bug-hunting tool VEGA discovered GhostLock (CVE-2026-43499), a use-after-free vulnerability lurking in the Linux kernel since 2011.
WIRED — The flaw grants any logged-in user root access on unpatched systems without special permissions. It affects all major distributions; Ubuntu 24.04, 22.04, and 20.04 LTS remain vulnerable. Patch coverage is uneven.
The GhostLock vulnerability, identified as CVE-2026-43499, was discovered by the team at Nebula Security using their AI-powered bug-hunting tool, VEGA. The security flaw is a use-after-free vulnerability that had existed within the Linux kernel since 2011, remaining undetected by humans for over a decade.
Exploiting this flaw allows any user with basic login credentials to elevate their privileges to root level, granting full administrative control over the system. The vulnerability is widespread, affecting all major Linux distributions. Specifically, Ubuntu LTS versions 20.04, 22.04, and 24.04 are still susceptible to the attack.
In recognition of the discovery and its potential impact, Google awarded the researchers a bounty of $92,000. While patches are being deployed, the current state of coverage across different environments is inconsistent.
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Waiting for your click …
·