# kernel privilege escalation

Published articles for kernel privilege escalation.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## GhostLock (CVE-2026-43499) kernel privilege escalation: Patch released

DevFeed: [GhostLock (CVE-2026-43499) kernel privilege escalation: Patch released](<https://devfeed.tech/articles/ghostlock-cve-2026-43499-kernel-privilege-escalation-patch-released-53466.md>)

Original publisher: [Read original article](<https://almalinux.org/blog/2026-07-09-ghostlock/>)

Author: Andrew Lukoshko AlmaLinux Lead Architect

Published: 2026-07-09T00:00:00Z

Content type: news

Language: en

Sources: [AlmaLinux](<https://devfeed.tech/sources/blog-on-almalinux.md>)

Topics: [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [container escape](<https://devfeed.tech/topics/container-escape.md>), [Deadlock](<https://devfeed.tech/topics/deadlock.md>)

Tags: [container-escape](<https://devfeed.tech/tags/container-escape.md>), [cve](<https://devfeed.tech/tags/cve.md>), [deadlock](<https://devfeed.tech/tags/deadlock.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [kernel-privilege-escalation](<https://devfeed.tech/tags/kernel-privilege-escalation.md>), [patch](<https://devfeed.tech/tags/patch.md>), [privilege-escalation](<https://devfeed.tech/tags/privilege-escalation.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

AlmaLinux reports that GhostLock (CVE-2026-43499), a Linux kernel use-after-free vulnerability in real-time mutex priority-inheritance code, can enable unprivileged local root access and container escape. Patched kernels are now available in production repositories for AlmaLinux 8, 9, and 10.

### Source excerpt

Update: The fix is now in production The patched kernel for GhostLock (CVE-2026-43499) has been released to the production repositories for every affected AlmaLinux release -- 8, 9, and 10. You no longer need to enable the testing repo. Just run: sudo dnf clean metadata && sudo dnf upgrade sudo reboot The fixed versions released to production are kernel-4.18.0-553.141.2.el8_10 (AlmaLinux 8), kernel-5.14.0-687.24.1.el9_8 (AlmaLinux 9), and kernel-6.12.0-211.32.1.el10_2 (AlmaLinux 10), or higher. Confirm you are running the patched version with uname -r after rebooting. Most mirrors sync every few hours, so if the update is not available to you yet, try again a little later.

## Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

DevFeed: [Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild](<https://devfeed.tech/articles/copy-fail-and-dirtyfrag-linux-page-cache-bugs-in-the-wild-49001.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/copy-fail-dirtyfrag-linux-page-bugs-in-the-wild>)

Author: Ruben Groenewoud,Eric Forte,Samir Bousseaden

Published: 2026-05-09T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [go](<https://devfeed.tech/tags/go.md>), [kernel-privilege-escalation](<https://devfeed.tech/tags/kernel-privilege-escalation.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [metasploit](<https://devfeed.tech/tags/metasploit.md>), [page-cache-corruption](<https://devfeed.tech/tags/page-cache-corruption.md>), [platform-internals](<https://devfeed.tech/tags/platform-internals.md>), [poc](<https://devfeed.tech/tags/poc.md>), [privilege-escalation](<https://devfeed.tech/tags/privilege-escalation.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Elastic Security Labs analyzes the Linux kernel privilege-escalation vulnerabilities Copy Fail and DirtyFrag, which exploit page-cache corruption to gain root access. The research also describes detection logic based on exploitation behavior and underlying primitives rather than individual proof-of-concept implementations.

### Source excerpt

This research analyzes the Linux kernel privilege escalation vulnerabilities Copy Fail and DirtyFrag, which exploit subtle page cache corruption bugs to create reliable paths to root access. Additionally, Elastic Security Labs is releasing detection logic for these vulnerabilities.

## CVE-2026-31431: "Copy Fail" Linux kernel flaw lets local users gain root in seconds

DevFeed: [CVE-2026-31431: "Copy Fail" Linux kernel flaw lets local users gain root in seconds](<https://devfeed.tech/articles/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds-53206.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds>)

Author: Michael Clark

Published: 2026-04-30T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [af-alg-exploit](<https://devfeed.tech/tags/af-alg-exploit.md>), [algif-aead-vulnerability](<https://devfeed.tech/tags/algif-aead-vulnerability.md>), [authencesn-aes-cbc-hmac-sha256](<https://devfeed.tech/tags/authencesn-aes-cbc-hmac-sha256.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [file-permissions](<https://devfeed.tech/tags/file-permissions.md>), [kernel-privilege-escalation](<https://devfeed.tech/tags/kernel-privilege-escalation.md>), [kernel-vulnerability](<https://devfeed.tech/tags/kernel-vulnerability.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-aead-vulnerability](<https://devfeed.tech/tags/linux-aead-vulnerability.md>), [linux-crypto-api-security](<https://devfeed.tech/tags/linux-crypto-api-security.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [linux-kernel-cloud-workload-vulnerability](<https://devfeed.tech/tags/linux-kernel-cloud-workload-vulnerability.md>), [linux-kernel-exploit-2026](<https://devfeed.tech/tags/linux-kernel-exploit-2026.md>), [linux-kernel-vulnerability](<https://devfeed.tech/tags/linux-kernel-vulnerability.md>), [page-cache-corruption](<https://devfeed.tech/tags/page-cache-corruption.md>), [poc](<https://devfeed.tech/tags/poc.md>), [python](<https://devfeed.tech/tags/python.md>), [scatterlist-exploit](<https://devfeed.tech/tags/scatterlist-exploit.md>), [security](<https://devfeed.tech/tags/security.md>), [sockets](<https://devfeed.tech/tags/sockets.md>), [splice-syscall-vulnerability](<https://devfeed.tech/tags/splice-syscall-vulnerability.md>), [sysdig-threat-research](<https://devfeed.tech/tags/sysdig-threat-research.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article analyzes CVE-2026-31431, a Linux kernel vulnerability in the userspace crypto interface that can let an unprivileged local user corrupt page-cache data and obtain root access. It covers affected kernel versions, the fix, exploitation details, and runtime detection coverage.

### Source excerpt

A newly analyzed Linux kernel vulnerability in algif_aead allows unintended writes into page cache memory via AF_ALG sockets and splice(). Learn how this behavior could bypass file permissions and what it means for cloud security.