by CloudLinux OS team | Jul 8, 2026 | СloudLinux Blog
📋 TL;DR — last updated July 10, 2026, 20:00 UTC GhostLock (CVE-2026-43499, CVSS 7.8 High) is a use-after-free bug in the Linux kernel’s futex priority-inheritance path that lets any local unprivileged user become root. A public full-chain proof-of-concept...
by CloudLinux OS team | Jul 8, 2026 | СloudLinux Blog
In early July 2026, researcher Jaeyoung Chung (CompSec Lab, Seoul National University) published a proof-of-concept for Bad epoll, a use-after-free bug in the Linux kernel’s epoll subsystem. On CloudLinux 9 and 10 it lets an unprivileged local user escalate to...
by CloudLinux OS team | Jul 7, 2026 | СloudLinux Blog
On July 6, 2026, researcher Hyunwoo Kim (@v4bel) publicly disclosed Januscape, a vulnerability in the Linux kernel’s KVM/x86 memory-management code. It has two attack paths. A malicious virtual machine can break out of the guest and run code as root on the host...
by CloudLinux OS team | Jul 2, 2026 | СloudLinux Blog
DirtyClone (CVE-2026-43503) is a Linux kernel local-privilege-escalation in the networking stack, disclosed with a public proof-of-concept from JFrog Security Research. It is not a new class of bug. It is the third named exploit of the same shared-fragment-marker...
by CloudLinux OS team | Jul 1, 2026 | СloudLinux Blog
A public, working proof-of-concept named IPv6 Frag Escape (ipv6_frag_escape) turns an unprivileged local user — including one confined inside an unprivileged container — into root on the host. It exploits a bug in the Linux kernel’s IPv6 output path present in...
by CloudLinux OS team | Jun 26, 2026 | СloudLinux Blog
On June 17, 2026, researcher Massimiliano Oldani published a working proof-of-concept named packet_edit_meme for a Linux kernel local privilege escalation now tracked as CVE-2026-46331 and nicknamed pedit COW. The flaw is in the kernel’s traffic-control (tc)...
Recent Comments