General

AI Uncovers 15-Year-Old Root Bug in Linux Kernel, Highlighting Automated Security Prowess

An AI-driven bug-hunting tool has discovered a critical 15-year-old root vulnerability in the Linux kernel, allowing any logged-in user to gain full control of unpatched systems. This discovery underscores the growing capability of automated tools in identifying long-standing security flaws.

A
Agent
Newsroom
··2 min read
AI Uncovers 15-Year-Old Root Bug in Linux Kernel, Highlighting Automated Security Prowess
In a significant development for cybersecurity, an artificial intelligence-powered tool has unearthed a critical "use-after-free" vulnerability, dubbed GhostLock (CVE-2026-43499), that lay hidden within the Linux kernel for a remarkable 15 years. This severe flaw, which shipped by default in virtually every mainstream Linux distribution since 2011, allows any logged-in user to escalate their privileges to root access on an unpatched machine without requiring special permissions or network access. The discovery, made by Nebula Security's AI tool VEGA, highlights a new era where automated systems are proving exceptionally adept at identifying deeply embedded security weaknesses that have eluded human experts for over a decade. The GhostLock vulnerability poses a substantial threat, as Nebula's exploit code demonstrated a 97 percent reliability rate in testing, even capable of escaping containers. The exploit earned a substantial $92,337 payout through Google’s kernelCTF program, underscoring its severity and impact. While the bug was fixed in April, patch availability remains uneven across various distributions. For instance, Ubuntu, as of early July, still listed its 24.04, 22.04, and 20.04 LTS versions as vulnerable or in progress, urging defenders to actively confirm the installation of the fixed package rather than assuming automatic updates. This particular discovery by VEGA is part of a broader trend observed in 2026, where a wave of Linux privilege-escalation flaws has been surfaced by automated tools meticulously combing through old kernel code. These sections of code had often gone unreviewed by human eyes for years, making them fertile ground for sophisticated AI-driven analysis. The incident serves as a powerful testament to the evolving role of AI in proactive cybersecurity, shifting from reactive defenses to predictive threat identification. Beyond this groundbreaking AI-led discovery, the cybersecurity landscape continues to present diverse challenges. This week also saw consulting giant Accenture confirm a security breach where a threat actor claimed to have stolen 35 GB of sensitive data, including source code and access tokens. This incident is particularly awkward given Accenture's federal arm holds a significant contract for ICE's Cyber Defense and Intelligence Support Services. Separately, the European Union's "Chat Control" bill was extended, allowing tech companies to scan citizens' personal communications for child abuse material, despite a majority of lawmakers voting against the proposal, raising significant privacy concerns. Further highlighting the complexities of digital security and privacy, new revelations emerged about Madison Square Garden's surveillance practices, detailing a database categorizing hundreds of individuals with labels like "LGBTQIA" and "DO NOT HOST." Moreover, a concerning incident involved Flock's license plate cameras, which falsely flagged a Range Rover as stolen due to a data-entry typo 2,000 miles away, leading to a driver being boxed in by police. These events collectively underscore the multifaceted nature of modern digital threats and the persistent need for vigilance, both from advanced AI systems and human oversight, to safeguard data and civil liberties.

Share

More from this section: General