Skip to content

Ghostlock: 15-Year-Old Root Vulnerability Discovered in Linux Kernel

At a glance: A root vulnerability in the Linux kernel since 2011 enables local privilege escalation and requires kernel updates across all affected systems.

A security vulnerability in the Linux kernel has existed since version 2.6.39 from 2011 and enables unauthenticated local access with root privileges. A patch is available but has not yet been deployed across all affected systems.

The vulnerability named Ghostlock was identified in the Linux kernel starting from version 2.6.39 and thus affects nearly every Linux system distributed since 2011 that has not been updated. It allows local attackers to execute code with root privileges.

For CISOs, this represents a critical inventory and patch management task: all Linux-based systems in the infrastructure – from servers to container platforms to IoT devices – must be checked against kernel versions that contain this vulnerability. Particularly problematic are production systems with long release cycles, embedded systems, and devices with frozen kernel versions.

While the patch has already been published, its distribution remains uneven. Distributions such as Ubuntu have provided security updates in some cases, but many older systems – particularly in critical infrastructure – are still running vulnerable versions. Prioritization according to system criticality and network exposure is necessary.


Source: www.golem.de · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: