TGViewer
cKure Red cKure Red @ckured · 2.77K subscribers
Post #753 1.79K
🐧GhostLock (CVE-2026-43499): a 15-year-old Linux kernel vulnerability that affects every distribution. Desktop, server, Android, IoT, embedded. $92,337 Google kernelCTF bounty.

A stack-UAF in the rtmutex subsystem. remove_waiter() uses current instead of waiter::task during proxy-lock rollback in futex_requeue(), leaving a dangling pointer to freed kernel stack memory. No special kernel modules needed, only CONFIG_FUTEX_PI which is enabled on every distro.

Nebula Security (NebuSec) turned it into a 97% stable privilege escalation and container escape. The exploit chains a dangling pointer into an arbitrary address write, hijacks a function table for control flow, and achieves root in about 5 seconds. Found by VEGA, their AI vulnerability scanner.

Part of IonStack, the first browser-to-kernel full-chain RCE on Android 17: CVE-2026-10702 (Firefox IonMonkey JIT 0-day, near 100% success rate) chained with GhostLock for kernel LPE.

Present since Linux 2.6.39 (2011). Fixed in Linux 7.1. Full exploit code published on GitHub.


Exploit:

https://github.com/NebuSec/CyberMeowfia/tree/main/IonStack/CVE-2026-43499
  • 👍 4
More from @ckured
  1. Oct 3, 2026Update: Archivegenocide has now crossed 200,000 videos & images, which is almost triple wh…
  2. Sep 29, 2026📱 Telegram OSINT tactics
  3. Sep 26, 2026☁️ Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops…
  4. Sep 23, 2026Alleged Google Pixel 10 Zero Day at 2.5K USD only as chain included some n-days. An intere…
  5. Sep 18, 2026AliExpress spyware caught using side channel attack to compromise hardware.
  6. Sep 17, 2026😒 Claude Code was used to make missile guidance system for 9 months by Houthis using mult…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →