Linux Kernel (GhostLock, DirtyClone)
A Linux kernel local privilege escalation vulnerability, named "GhostLock" (with CVE-2026-43499), has been identified in the Linux kernel's rtmutex / futex locking subsystem. If the vulnerability is exploited, it allows a local authenticated attacker to escalate privileges on affected Linux system.
A variant of recently disclosed Dirty Frag, namely "DirtyClone" (with CVE-2026-43503), has been identified in the Linux kernel's networking stack, specifically in socket buffer (sk_buff) fragment handling. The vulnerability could allow a local unprivileged attacker to corrupt page-cache-backed memory and obtain root-level privileges on affected Linux systems.
- CVE-2026-43499 affects certain ASUSTOR products that have Linux kernel versions higher than 2.6.39 and ADM versions ranging from 4.1 to 5.1. Updates with Linux Kernel Patch will be released as soon as possible.
- CVE-2026-43503 affects certain ASUSTOR products that have Linux kernel versions higher than 4.11 and ADM versions ranging from 4.1 to 5.1. Updates with Linux Kernel Patch will be released as soon as possible.