AlmaLinux List Archives
Sign In Sign Up
Manage this list Sign In Sign Up

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

Security

Thread Start a new thread
Download
Threads by month
  • ----- 2026 -----
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2025 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
security@lists.almalinux.org

July 2026

  • 1 participants
  • 1 discussions
GhostLock (CVE-2026-43499) kernel LPE - patched kernels in testing repo now
by Jonathan Wright 09 Jul '26

09 Jul '26
Hello AlmaLinux Community! It's me again! Patched kernels for GhostLock (CVE-2026-43499), a newly disclosed Linux kernel local privilege escalation, are available in the almalinux-testing repository right now, and we need your help verifying them before we promote them to production. WHY THIS MATTERS GhostLock is a use-after-free in the kernel's rtmutex priority inheritance code. An unprivileged local user can exploit it to gain root, and it works from inside a container to escape to the host. No special capabilities are required, and all supported AlmaLinux releases (8, 9, and 10) are affected. The bug has been present in the kernel since 2011. Our core team has backported the upstream fix to every affected branch, and ALESCo approved shipping ahead of the CentOS Stream / RHEL update. Community testing is what gets these kernels safely into production, so please help if you can. HOW TO TEST 1. Install the testing repo: sudo dnf install -y almalinux-release-testing 2. Update the kernel: sudo dnf update 'kernel*' --enablerepo=almalinux-testing 3. Reboot: sudo reboot 4. Confirm the patched kernel is running: uname -r rpm -q kernel Patched versions (or higher): AlmaLinux 8: kernel-4.18.0-553.141.2.el8_10 AlmaLinux 9: kernel-5.14.0-687.23.2.el9_8 AlmaLinux 10: kernel-6.12.0-211.31.2.el10_2 Unless this is a non-production environment, we recommend disabling the testing repo once you've updated: sudo dnf config-manager --disable almalinux-testing REPORT RESULTS Whether things work or break, we want to hear from you as soon as possible: - AlmaLinux Chat: https://chat.almalinux.org - Bug tracker: https://bugs.almalinux.org Full technical details, including how the vulnerability works, are in the blog post: https://almalinux.org/blog/2026-07-09-ghostlock/ Thank you for helping us keep AlmaLinux secure!
1 0
0 0

HyperKitty Powered by HyperKitty version 1.3.12.