藏在 Linux futex 15 年的 PI 洞:CVE-2026-43499 GhostLock 讓本地帳號 5 秒拿到 root
GhostLock(CVE-2026-43499)是 rt_mutex 的 use-after-free,2011 年寫進 2.6.39、直到 Linux 7....
2 篇文章
GhostLock(CVE-2026-43499)是 rt_mutex 的 use-after-free,2011 年寫進 2.6.39、直到 Linux 7....
Linux kernel 的 algif_aead 有一條九年前寫下的 splice 優化路徑,讓非特權使用者能對 page cache 做出可控寫入。CVE-...