A Stack Use-After-Free Vulnerability Hiding in Linux for 15 Years
Based on NebuSec Research
2024
Uncovering a critical vulnerability that went unnoticed for over a decade
The UAF bug enters the Linux codebase
Exists across all major distributions undetected
NebuSec researchers identify and disclose GhostLock
Fix deployed across Linux distributions
Understanding why this discovery matters for the security community
Every Linux distribution was vulnerable, affecting millions of systems
15 years provided ample time for potential exploitation
Evaded numerous security audits and code reviews
Stack UAF vulnerabilities can lead to privilege escalation
Security research keeps our systems safe. Stay informed, stay secure.