Correction, September 17, 2026: The earlier GhostLock label, five-second root claim, and Android tap-to-compromise scenario could not be substantiated by the cited primary records and are withdrawn. CVE-2026-43499 is a local memory-corruption issue in Linux rtmutex handling. This revision follows the Linux CNA record.
What the flaw does
The rtmutex mechanism handles priority inheritance in kernel locking. During futex proxy-lock rollback, remove_waiter() operates on the current task instead of the waiting task. Incorrect locking and an uncleared pointer can cause use-after-free and kernel-memory corruption, creating a path to privilege escalation or a kernel crash.
The Linux CNA rates this CVSS v3.1 7.8 HIGH. A basic unprivileged local user able to issue futex system calls can reach the vulnerable path. It is not directly reachable over a network. This record alone does not establish a virtual-machine-to-host escape or guaranteed success on all devices.
Identify the fixed package
The record lists upstream fixes in the respective branches: 5.10.261, 5.15.212, 6.1.175, 6.6.140, 6.12.86, 6.18.27, 7.0.4, and 7.1. Distribution vendors may backport the fix into packages with older upstream numbers. Compare the vendor's CVE status and package changelog rather than treating these as universal minimum versions.
- ✓Identify the kernel provider and installed package on servers and container hosts
- ✓Install the vendor-confirmed fix for CVE-2026-43499 through official channels
- ✓Complete a required reboot or the vendor's supported live patch, then verify the running kernel
- ✓Reduce unnecessary local accounts and code-execution permissions, and investigate unexpected privilege changes or kernel crashes
Web-server headers and guessed Nginx blocking rules do not repair kernel futex handling. The previous configuration example is withdrawn as remediation. Access restrictions can reduce exposure while the update is scheduled, but they do not replace the kernel fix.
