Nebula Security

Topic

CVE-2026-43499

IonStack part III: Rooting Android 17 with GhostLock

July 15, 2026 Android

IonStack part III: Rooting Android 17 with GhostLock

GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by Nebula Security that exists in every major distribution since 2011. After turning it into a stable privilege escalation and container escape, we took one step further and used GhostLock to develop the world’s first public Android 17 root. This writeup covers the additional exploit techniques used to migrate the exploit for Android.

12 min read

IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years

July 7, 2026 linux

IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years

GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.

17 min read