CVE-2026-53166Patch

MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

4.0/ 10 priority

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-07-08); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-07-08: 2Mentions · 2026-07-11: 2Mentions · 2026-07-21: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-08-11: 1Exploit Tool / Code · 2026-07-08: 1Exploit Tool / Code · 2026-08-11: 1Patch / Workaround · 2026-07-08: 2Patch / Workaround · 2026-07-11: 2Patch / Workaround · 2026-07-21: 1Technical Details · 2026-07-08: 2Technical Details · 2026-07-11: 1Technical Details · 2026-07-21: 1Technical Details · 2026-08-11: 107-0807-1107-2108-11
Signal classification3 categories
Patch
350.0%
Exploit
233.3%
Disclosure
116.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-07-082
Exploit1Patch1
2026-07-112
Patch2
2026-07-211
Disclosure1
2026-08-111
Exploit1
Full discourse6 posts
  • Teegra 🧝‍♀️𝕏@Teeegra
    Exploit

    محققان شرکت Nebula Security یک آسیب‌پذیری ۱۵ ساله در هسته لینوکس (Linux kernel) با شناسه CVE-2026-43499 موسوم به GhostLock را فاش کردند که به هر کاربر عادی اجازه می‌دهد کنترل کامل سیستم را با سطح دسترسی ریشه (root) به دست گیرد. این نقص از نوع استفاده پس از آزادسازی حافظه (use-after-free) است، از سال ۲۰۱۱ در تقریباً تمام توزیع‌های اصلی لینوکس وجود داشته و نیازی به تنظیمات خاص یا دسترسی شبکه ندارد! بهره‌برداری (exploit) ساخته‌شده توسط این تیم در آزمایش‌ها ۹۷ درصد موفقیت داشته، قادر به فرار از محیط‌های ایزوله‌شده (container escape) است و گوگل مبلغ ۹۲٬۳۳۷ دلار از طریق برنامه kernelCTF به این تیم پرداخت کرده است. کد بهره‌برداری به‌صورت عمومی منتشر شده، هرچند تاکنون سوءاستفاده‌ای در دنیای واقعی گزارش نشده است! وصله امنیتی (patch) این آسیب‌پذیری در آوریل منتشر شد، اما نصب آخرین نسخه هسته توصیه می‌شود، زیرا اولین نسخه اصلاح‌شده خود یک باگ جداگانه (CVE-2026-53166) ایجاد کرده بود. توزیع‌هایی مانند اوبونتو (Ubuntu) هنوز برخی نسخه‌های LTS خود را وصله نکرده‌اند. اهمیت این آسیب‌پذیری فراتر از دسترسی محلی است؛ Nebula نشان داده که GhostLock در ترکیب با یک آسیب‌پذیری مرورگر فایرفاکس (Firefox) در قالب زنجیره‌ای موسوم به IonStack، می‌تواند از طریق کلیک روی یک لینک مخرب، کنترل کامل دستگاه اندرویدی را از راه دور در اختیار مهاجم قرار دهد! این آسیب‌پذیری بخشی از روند نگران‌کننده‌ای است که در آن ابزارهای هوش مصنوعی مانند VEGA نقص‌های قدیمی اما خطرناک هسته لینوکس را کشف می‌کنند.

    Post summary

    Nebula Security exposed a 15‑year‑old Linux kernel use‑after‑free flaw (CVE‑2026‑43499), released a functional exploit and PoC, but no real‑world attacks were reported; a patch was issued in April, yet the first update introduced a new bug, and the flaw can be chained with a Firefox vulnerability for remote Android takeover.

    02034122.2K
    19.4K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    Patching is not fully simple. The first GhostLock fix caused another bug, CVE-2026-53166, which could crash systems. #Linux distro patches were still uneven in early July. Learn more: https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html https://t.co/stZ2tgwlpn

    Post summary

    The post discusses how patching GhostLock introduced a new CVE that can crash systems, highlighting patching challenges rather than exploitation or counterfeit claims.

    0101106.3K
    2.3M followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #Kernel_Security #Mobile_security IonStack Vulnerability Chain Part 1 - https://nebusec.ai/research/ionstack-part-1-cve-2026-10702 Unsound IonBanana Peel in Ion Compiler, Slipping Through Firefox's SpiderMonkey JIT // IonMonkey CVE-2026-10702 https://github.com/NebuSec/CyberMeowfia/tree/main/IonStack Part 2 - https://nebusec.ai/research/ionstack-part-2/ GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years // GhostLock (CVE-2026-43499) + CVE-2026-53166 Part 3 - https://nebusec.ai/research/ionstack-part-3/ Rooting Android 17 with GhostLock // Using GhostLock to develop the world's first public root for Android 17 // http://www.cyberpocket.org

    Post summary

    The post announces a chain of vulnerabilities covering the Ion compiler and GhostLock, shares PoC code via GitHub, and claims Android 17 can be rooted using GhostLock.

    00001190
    3.4K followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    2011'den beri Linux çekirdeğinde saklı: %97 başarı oranıyla 5 saniyede root yetkisi! Nebula Security, VEGA adlı AI aracıyla CVE-2026-43499'u (GhostLock) keşfetti — Linux 2.6.39'daki rtmutex alt sistemi yeniden tasarımından kaynaklanan bir açık. Neredeyse tüm popüler dağıtımları etkiliyor. • futex_requeue() işlemi kilitlenmeyi tespit edip geri alırken, uyuyan bir iş parçacığının bekleme nesnesine hatalı erişiyor — bu da use-after-free açığına dönüşüyor. • Hiçbir özel yetki, çekirdek değişikliği veya ağ erişimi gerekmiyor; container'dan kaçış dahil root erişimi elde ediliyor. • Araştırmacılar Google'ın kernelCTF programından 92.337 dolar ödül aldı; ilk yama ikinci bir çökme açığına (CVE-2026-53166) yol açtığı için en güncel çekirdek sürümü önerilir. Squidbleed ve curl açığından sonra bir 15 yıllık kernel açığı daha AI ile gün yüzüne çıktı — eski kod artık hiç olmadığı kadar taranıyor! #SiberGüvenlik #Linux #YapayZeka

    Post summary

    Nebula Security uncovered a use‑after‑free vulnerability in Linux kernel 2.6.39, named GhostLock (CVE‑2026‑43499), and recommends upgrading to the latest kernel due to a patch that introduced a second crash.

    0000064
    36 followersView on X
  • tec4net@tec4net
    Patch

    Linux-Kernel-Schwachstelle ermöglicht Angreifern Root-Rechte Eine seit 2011 bekannte Schwachstelle im Linux-Kernel sorgt aktuell für erhebliche Sicherheitsbedenken. Die unter CVE-2026-43499 bekannte Lücke mit dem Namen „GhostLock“ betrifft das rtmutex/futex-Subsystem und ermöglicht unter bestimmten Voraussetzungen eine lokale Rechteausweitung bis hin zu Root-Zugriffen. Die Ursache liegt in einem Fehler im Locking-Code des Kernels, der einen sogenannten Use-after-Free-Fehler auslöst. Dafür reicht ein gewöhnlicher Threading-Aufruf eines lokalen Programms mit normalen Benutzerrechten aus. Besonders kritisch ist, dass nahezu alle Linux-Distributionen der vergangenen 15 Jahre betroffen sein können. Zusätzlich erhöht ein bereits verfügbarer Root-Exploit mit hoher Erfolgswahrscheinlichkeit die Dringlichkeit. Auch Container-Umgebungen wie Docker oder Kubernetes sind betroffen, da die Schwachstelle unter bestimmten Bedingungen einen Ausbruch aus Containern ermöglichen kann. Sicherheitsupdates stehen inzwischen für verschiedene Kernel-Versionen bereit. Unter anderem wurden Korrekturen für die Versionen 6.1.175, 6.6.140, 6.12.86, 6.18.27 und 7.0.4 veröffentlicht. Administratoren sollten ihre Systeme zeitnah aktualisieren und auch die zusätzliche Schwachstelle CVE-2026-53166 berücksichtigen. Besonders Betreiber von Multi-Tenant-Servern, Container-Plattformen oder Systemen mit externen Benutzerzugängen sollten die Sicherheitsmaßnahmen überprüfen. Ergänzend können in Container-Umgebungen technische Schutzmaßnahmen wie angepasste Seccomp-Profile helfen, um betroffene Systemaufrufe einzuschränken. Quelle: https://linuxnews.de/ghostlock-15-jahre-alte-kernel-luecke-ermoeglicht-root-zugriff/ ISO 27001 – Informationssicherheit strukturiert erfolgreich einführen https://www.tec4net.com/web/iso-27001/ Wir sind Experten für Datenschutz und IT-Sicherheit Profitieren Sie von unserer umfassenden Beratung zu den Themen Datenschutz und IT-Sicherheit. Unser erfahrenes Team unterstützt Sie dabei, Ihre Website und digitalen Dienste datenschutzkonform zu gestalten um die gesetzlichen Vorgaben zu erfüllen. Kontaktieren Sie uns noch heute und sichern Sie sich praxisnahe Beratung zur Umsetzung der DSGVO und Normen wie ISO 27001, PCI-DSS oder TISAX. Datenschutz und IT-Sicherheit praktikabel umsetzen – tec4net GmbH http://www.tec4net.com – http://www.it-news-blog.com – http://www.it-sachverstand.info – http://www.datenschutz-muenchen.com – http://www.it-sicherheit-muenchen.com Alle unsere NEWS -> http://news.tec4net.com

    Post summary

    The article alerts to the long‑standing CVE‑2026‑43499 "GhostLock" vulnerability, outlines its technical impact, and emphasizes the availability of kernel patches, urging prompt system updates.

    0000075
    56 followersView on X
  • Stanislav@stanislavdevops
    Patch

    Severity is High, not critical, because it needs local access. That is how you rank it: if you run untrusted code on a shared kernel, patch tonight. Also watch the follow-up bug CVE-2026-53166. Who is exposed and how to check: https://privatedevops.com/news/ghostlock-cve-2026-43499-linux-kernel-root-who-is-at-risk

    Post summary

    The text announces the CVE‐2026‑43499 Linux kernel vulnerability and urges users to patch promptly, without providing proof of concept, exploit code, or evidence of active exploitation.

    0000050
    1 followersView on X

Explore more