[HPC-NEWS] ADA Cloud: CVE-2026-43499 GhostLock – action required on VMs
HPC Cineca
portal at hpc.cineca.it
Thu Jul 9 15:27:59 CEST 2026
ADA Cloud: CVE-2026-43499 GhostLock – action required on VMs (https://www.hpc.cineca.it/newsletter/ada-cloud-cve-2026-43499-ghostlock-action-required-on-vms/)
9 July 2026
Dear Users,
This is to inform you regarding the very recent linux kernel vulnerability CVE-2026-43499 GhostLock, that may allow a local user to gain root privileges in your Virtual Machines. [1] [2]
It is thus required to fix the vulnerability as soon as possible on your VMs:
Apply the latest available kernel updates from your Linux distribution.
Reboot systems where required to ensure the patched kernel is active.
Prioritize shared, multi-tenant, container-hosting, and CI/CD environments, and if you have unprivileged users with shell access to your VM, as these are considered higher-risk scenarios.
Let us know in case of issues, sending an email to superc at cineca.it (mailto:superc at cineca.it)
HPC Cloud Support.
[1] 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros (https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html?m=1)
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-43499 (https://nvd.nist.gov/vuln/detail/CVE-2026-43499)
To unsubscribe to HPC-News send a mail to hpc-news-userdb-leave at list.cineca.it (mailto:hpc-news-userdb-leave at list.cineca.it) .
For more information see documentation at https://www.hpc.cineca.it/user-support/get-in-touch/ (https://www.hpc.cineca.it/user-support/get-in-touch/)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://list.cineca.it/pipermail/hpc-news/attachments/20260709/be18b1c5/attachment.htm>
More information about the Hpc-news
mailing list