GhostLock 15‑Year Flaw Lets Users Root Linux
The ghostlock 15-year flaw discovered by Nebula Security researchers affects numerous Linux distributions, posing a significant security risk. This longstanding vulnerability, known as CVE-2026-43499, permits any logged-in user to gain full root control on any unpatched machine. Remarkably, the flaw, which originated over a decade ago, has been included by default in nearly all mainstream distributions since 2011. The flaw requires no special permissions, extraordinary settings, or network connection to exploit, making it a critical concern for system administrators.
Researchers emphasize the urgency of addressing this vulnerability in order to secure affected systems. They recommend systems administrators patch their Linux distributions promptly to prevent potential exploitation. The discovery of the ghostlock 15-year flaw underscores the importance of regular security audits and updates within the Linux ecosystem.
For more comprehensive information on this vulnerability, including potential mitigation strategies, readers are encouraged to explore the full article at the provided link.
https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
