@nebusecurity: GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as…
Summary
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel 0-day used in the IonStack full chain exploit, affecting all Linux devices from IoT to desktops. Nebu Security won a $92,337 bug bounty and published the exploit on GitHub.
View Cached Full Text
Cached at: 07/08/26, 04:26 AM
GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit.
Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected.
Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below https://t.co/WB42YSBUWj
Similar Articles
GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel stack use-after-free vulnerability affecting all distributions, allowing local privilege escalation and container escape. Detailed exploitation techniques are presented.
Reporting a 19+ Years Hidden Linux Kernel Zero-Day for Google kernelCTF: CVE-2026-43456
A Linux kernel zero-day vulnerability (CVE-2026-43456) rooted in code from 2007 was discovered by Yuki Koike and Kota Toda, rewarded over $80,000 via Google's kernelCTF. The flaw, a type confusion in the net/bonding subsystem, allows reliable privilege escalation within one second.
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
AI tool VEGA from Nebula Security discovered a 15-year-old use-after-free bug in the Linux kernel (GhostLock) that allows any logged-in user to gain root access. The flaw, present since 2011, was patched in April but rollout is uneven.
Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability
Researchers used an autonomous system to discover a critical heap buffer overflow vulnerability in NGINX's rewrite module (CVE-2026-42945), present since 2008, enabling remote code execution. Multiple CVEs were confirmed by NGINX.
CVE-2026-40369: Arbitrary Kernel Address Increment via NtQuerySystemInformation
CVE-2026-40369 describes a vulnerability in Windows kernel's NtQuerySystemInformation function that allows arbitrary kernel address increment, enabling privilege escalation from unprivileged processes including Chrome sandbox. The exploit is deterministic on Windows 11 24H2-25H2.