If you're just now hearing about GhostLock and looking to fix it, make sure you don't introduce two unpriv-reachable DoSes associated with its fixes. The fix the Linux CNA lists for CVE-2026-43499 introduces a NULL deref, which caused CVE-2026-53166 to be issued. Unfortunately...
Foundational security for the Linux kernel. Solving the most difficult memory unsafety problems. Created by @opensrcsec
Joined June 2012
- KERNSEAL makes the linear page cache overflow in cyberstan.co.uk/fuse-readdir-o… deterministically unexploitable. Serial log below 👇
- It's now available!We expect our 7.0 beta to be available for testing within the next two weeks.
- We expect our 7.0 beta to be available for testing within the next two weeks.
- We've just published a Knowledge Base article with more information about the vulnerability, current published/unpublished exploits, and current mitigations. We still recommend patching ASAP.Exploits are now appearing targeting pidfd, which is forced into all Linux kernels since 5.10 (2020), no module or initcall to blacklist this time, must patch ASAP!

