GhostLock은 15년간 존재해온 Linux 취약점으로, 로컬 공격자가 루트 권한을 획득할 수 있다.
GhostLock(CVE-2026-43499)는 15년간 모든 Linux 배포판에 존재했던 스택 UAF 취약점이다. 이 취약점은 비특권 로컬 공격자가 스레딩 시스템 호출을 통해 발생시킬 수 있으며, 이를 이용해 루트 권한을 획득하고 컨테이너에서 탈출할 수 있다. 이는 Linux 커널 2.6.39부터 도입되어 7.1에서 수정된 문제로, 심각성이 높아 보인다.
GhostLock is a 15-year-old Linux vulnerability allowing local attackers to gain root privileges.
GhostLock (CVE-2026-43499) is a stack UAF vulnerability present in all Linux distributions for 15 years. It allows non-privileged local attackers to trigger the UAF through typical threading system calls, potentially leading to root privilege escalation and container escape. This issue was introduced in Linux kernel 2.6.39 and was patched in 7.1, making it a serious threat.