Campfire
Archive Tags About

IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years

Visit link →
Screenshot of IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
July 17, 2026
linux security
Permalink: 2026/w29/ionstack-part-ii-ghostlock-a-stack-uaf-that-has-existed-in-a

Related Links

  • Watch This Before You Set Up Hermes (NetBird Remote Access) linux security
  • Debian -- News -- Updated Debian 13: 13.6 released linux security
  • Cockpit: The Easiest Way to Manage Linux Servers linux security
  • Homebrew 6.0.0 security linux
  • Copy Fail — 732 Bytes to Root linux security
← Back to Week 29

© 2026 Timo Sugliani · Weekly curated links, shared around the tech campfire