NEWS
GhostLock’s Phone Demo Forced Shared Linux Hosts to Patch
IonStack rooted Android 17 from a Firefox URL, but GhostLock is a 2011 Linux kernel hole that also breaks shared Docker and CI hosts.
Nebula Security’s IonStack chain roots Android 17 from one Firefox URL by pairing a JIT bug with GhostLock, a 2011 Linux kernel hole that also escapes containers. Mozilla closed the webpage door in Firefox 151.0.3 on June 2, 2026. The kernel half is local, built in by default, and still the piece that follows an unpatched host into phones, CI fleets, and shared servers.
The company, a Y Combinator S26 lab, says its scanning agent found both bugs without a human aiming it at either codebase. Research posts call that agent Nebu. The product pitch calls it VEGA. The June 24, 2026 demo sold a phone hack. The kernel CVE is what operators actually had to patch.
IonStack Turns One Firefox Tab Into Kernel Root
CVE-2026-10702 is a miscompilation in SpiderMonkey’s Ion/Warp JIT. Nebula’s Part I writeup, dated July 10, 2026, says crafted JavaScript can win arbitrary code execution in the Firefox renderer. The lab also used the same bug against Tor Browser, which ships a Firefox engine. Mozilla’s Firefox 151.0.3 security advisory lists the issue as high impact and credits Nebula Security, pointing at Bug 2040903. The same bulletin, MFSA 2026-54, also ships CVE-2026-10701, a separate high-impact graphics bug from another reporter.
Renderer code is not yet root. On an ARM64 Android 17 build, Nebula chained that foothold into CVE-2026-43499, which it named GhostLock, and called the result the first public Android 17 root. GhostLock is not an Android-only defect. It lives in remove_waiter() in the kernel’s rtmutex code, the path that implements priority-inheritance futexes, and it is compiled in whenever CONFIG_FUTEX_PI is on, which is the default on ordinary distribution kernels.
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by Nebu that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF.
NebuSec, IonStack Part II
The lab put that claim on the record on July 8, 2026, and said any Linux device, IoT through desktop, sits in the blast radius until the kernel moves.
GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit.
Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected.
Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below pic.twitter.com/WB42YSBUWj
— NebuSec (@nebusecurity) July 8, 2026
IONSTACK NUMBERS
- Kernel score: NVD and Ubuntu both list GhostLock at CVSS 3.1 7.8, local, low complexity, low privilege.
- Kernel window: Linux v2.6.39-rc1 through v7.1-rc1, introduced in 2011, fixed in Linux 7.1.
- Firefox fix: 151.0.3, announced June 2, 2026, after a May 20 report.
- Bounty: Google’s kernelCTF paid $92,337 on June 30, 2026.
A 97% figure in that writeup is for the local root and container-escape path, not a field infection rate. Nebula says it has not presented evidence of in-the-wild attacks against users.
The Hosts That Share a Kernel With Strangers
A one-click phone demo needs Firefox on the device and a user who opens the page. GhostLock needs a local process that can make ordinary threading calls. On a laptop you own, that still means someone already runs code on the box. On a shared kernel, that local process can be a customer container, a CI job, or a build that arrived from a pull request.
That is why the overlooked party is not the Android 17 owner with auto-updates on. It is the operator who uses the kernel as the wall between tenants. Docker and Kubernetes do not replace that wall. They sit on it. AlmaLinux Lead Architect Andrew Lukoshko wrote on July 9, 2026, that an unprivileged local user can gain root and that the same primitive works from inside a container to the host, with no special capabilities required.
WHO HAD TO MOVE
- Shared Docker fleets: Kernel isolation is the customer boundary, so a container escape is a host breach.
- Kubernetes nodes: Untrusted pods that can issue futex and thread syscalls sit on the same vulnerable code path.
- Self-hosted CI runners: CircleCI told customers on those machines to patch the host themselves, because the company does not ship runner kernels.
- Multi-tenant VPS and shared hosting: CloudLinux treated every supported family as affected and pushed livepatches onto its main feed.
- Firefox 151.0.2 and older: The webpage entry is independent of the kernel and hits desktop, Android, and Tor Browser builds that still embed the buggy JIT.
Machine-executor CI jobs that already run as root do not gain a new secret by exploiting GhostLock. They can still destabilize the host. CircleCI patched those images anyway, then destroyed each VM at the end of the job as before.
Why CircleCI Rebooted the Docker Fleet Overnight
CircleCI’s engineering team opened emergency maintenance on July 9, 2026, at 21:00 UTC, two days after public disclosure. Docker jobs on that platform run on a shared Linux fleet. The company said it had no evidence of exploitation on its own infrastructure, then replaced kernels anyway because the security boundary between customers is the host kernel.
The Docker rollout finished on July 10, 2026, at 5:04 UTC, 8 hours and 4 minutes after the start. A small number of jobs were forcibly canceled and marked Infrastructure Fail. Self-hosted runner users were told to follow their distro’s guidance. There was no CircleCI binary to bump.
The CircleCI kernel update cannot be rolled back because it remediates a high-severity container-isolation vulnerability on the shared Docker fleet.
CircleCI engineering, incident post, July 2026
The people who felt that patch first were not Android testers. They were customers whose MongoDB 8.x service containers died on the new images. CircleCI published a workaround, GLIBC_TUNABLES=glibc.pthread.rseq=1 on the Mongo container, and pointed at MongoDB ticket SERVER-121912, which tracks a break on newer kernels. The GhostLock images could not be rolled back, the company said, after it had shipped patched kernel images for Docker jobs.
That is the hidden invoice. A 2011 cleanup bug in rtmutex forced a CI host to jump kernels on a shared fleet, and the jump landed on an unrelated userspace incompatibility. AlmaLinux pushed production kernels the same week: kernel-4.18.0-553.141.2.el8_10 for version 8, kernel-5.14.0-687.24.1.el9_8 for version 9, and kernel-6.12.0-211.32.1.el10_2 for version 10, or higher. Red Hat’s GhostLock bulletin, public on July 8, 2026, was still being updated on September 8, 2026, and said there is no module to unload and no sysctl that turns the path off.
A 2011 Helper Still Cleared the Wrong Thread
GhostLock is a stack use-after-free. The helper remove_waiter() was written for a thread that blocks on a lock, then cleans up after itself, so it clears current->pi_blocked_on. Requeue-PI later reused that helper on a proxy path, where the running thread is rolling back a waiter that belongs to someone else. On a deadlock rollback, the waiter task keeps a pointer into its own kernel stack frame after that frame is gone. Later priority-inheritance walks follow the stale pointer.
Nebula’s 15-year stack use-after-free writeup traces the mistake to the 2011 rtmutex rework in commit 8161239a8bcc, titled “rtmutex: Simplify PI algorithm and make highest prio task get lock.” The April 2026 fix, commit 3bfdc63936dd, makes the helper use waiter::task instead of current. The affected range is v2.6.39-rc1 through v7.1-rc1. That is about 15 years of production kernels, 2011 to 2026, with no extra privilege and no user-namespace trick required.
GHOSTLOCK DISCLOSURE CLOCK
- April 18, 2026: Nebula reports the bug, with a draft patch, to security@kernel.org.
- April 20, 2026: The kernel is fixed, two days after the report.
- May 4, 2026: The first backport lands on stable trees.
- June 30, 2026: Google acknowledges the kernelCTF submission and pays $92,337.
- July 7, 2026: Nebula publishes the GhostLock writeup.
- July 9, 2026: CircleCI starts emergency kernel maintenance; AlmaLinux ships production kernels.
A follow-up crash bug was assigned CVE-2026-53166 around the first fix, then the numbering authority rejected that ID. CloudLinux later told customers the extra commit had been reverted upstream and that finding CVE-2026-43499 in patch info is enough. Distros that raced the first backport still needed a current kernel, not the earliest tagged build.
There is no clean site workaround. The trigger is ordinary futex and threading syscalls. Nebula notes that RANDOMIZE_KSTACK_OFFSET turns stack reuse into a rough 1-in-64 guess and is not a substitute for the patch. The lab’s own policy on bugs its agent finds is 90+30 days. Kernel maintainers were faster than that policy on the fix itself. Public proof-of-concept code followed the writeup, which is why shared-kernel hosts had a short weekend.
Mozilla Shipped Firefox 151.0.3 Thirteen Days After the Report
The webpage half moved on a different clock. Nebula says it reported CVE-2026-10702 with an exploit to Mozilla on May 20, 2026. Mozilla acknowledged the same day, found the root cause the same day, and finished the fix the same day. Firefox 151.0.3 shipped 13 days later, on June 2, 2026.
The unsound step is in how Ion models MObjectToIterator when skip-registration is set. The compiler treated an operation as a read even though resolving a lazy property can allocate a new dynamic-slots buffer and free the old one. Global value numbering then reused a stale pointer. Nebula calls it the first SpiderMonkey JIT CVE after Firefox’s last-minute pre-Pwn2Own sweep, and says the bug still turned up after Anthropic Mythos had audited Firefox. The mitigation refined that instruction’s alias set so the optimiser cannot keep the dead pointer.
TWO PATCHES, TWO CLOCKS
| Component | CVE | Fix vehicle | Date |
|---|---|---|---|
| Firefox | CVE-2026-10702 | Firefox 151.0.3 (MFSA 2026-54) | June 2, 2026 |
| Linux kernel | CVE-2026-43499 | commit 3bfdc63936dd, Linux 7.1 | April 20, 2026 |
| CircleCI Docker fleet | GhostLock | host kernel images | July 10, 2026 |
| AlmaLinux 8 | GhostLock | kernel-4.18.0-553.141.2.el8_10 | July 9, 2026 |
Ubuntu’s firefox package on 22.04 and later is a stub that installs the snap, so Canonical marked those firefox packages not affected once the snap moved. Thunderbird on Ubuntu 22.04 was still listed as vulnerable in the June tracker because that release had not yet switched the package to a snap. Mozjs copies of SpiderMonkey were marked ignored, with the Ubuntu note that backporting JIT fixes into those trees is not feasible.
The browser patch kills IonStack’s remote first step. It does not patch GhostLock. A fully updated Firefox on an unpatched Android 17 kernel is no longer a one-URL root, and it is still a local-root kernel. Nebula’s Part III post, dated July 15, 2026, walks the extra work that was required to take GhostLock from a generic Linux privilege escalation to that Android 17 build, including a different stack-reclaim path and extra work against KASLR and CFI. Those steps stay in the research post. They are not a field manual.
Locked Android Phones Still Carry the Server Bug
Server distros could reboot. Phone kernels move through OEM bulletins, and that queue is slower. By late September 2026, public ports of GhostLock were still being aimed at locked-bootloader handsets and at gadgets that never got a 7.1-class backport. Ubuntu last updated its high-priority GhostLock kernel tracker on September 24, 2026, and still rates the issue High at 7.8.
The July conversation around Nebula’s post treated the bug as nearly universal Linux. The lab asked readers to name a Linux device that was not affected and said it would be surprised. The replies that followed were less about Android 17 marketing and more about old IoT and phones people already had a shell on. That read was correct. GhostLock does not care whether the process that trips it came from a Firefox renderer, a CI job, or a local app.
Firefox 151.0.3 is the fix for the tab. A current distro kernel, or a livepatch that carries 3bfdc63936dd, is the fix for the host. Until an OEM ships that backport, an Android 17 device can still lose a local argument to a 2011 cleanup helper that trusted the wrong thread.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
