RHSB-2026-010 Locking Subsystem Privilege Escalation - Linux Kernel (CVE-2026-43499, CVE-2026-53166) - "GhostLock"

Public Date: July 8, 2026, 19:05
Updated July 8, 2026, 19:05

Was this information helpful?

Feedback cancelled

Ongoing Status
Important Impact

Executive Summary

Red Hat is expediting the release of fixes for CVE-2026-43499 and CVE-2026-53166. These flaws were discovered in the Linux kernel's locking subsystem, related to mutexes. These could allow a local attacker to achieve privilege escalation or cause a denial of service. Environments that do not use real-time scheduling or Priority Inheritance futexes have reduced exposure, though the affected code paths are present in all standard kernel builds.

The investigation is ongoing and this bulletin will be updated as new information emerges. Log in with your Red Hat account, then click the "Follow" button below to be notified of changes to this bulletin.

Affected Products

The following Red Hat product versions are directly affected:

  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • Red Hat Enterprise Linux 10

Further, any Red Hat product that relies on the Red Hat Enterprise Linux kernel (including RHEL CoreOS) is also potentially impacted. This includes layered products such as Red Hat OpenShift Container Platform, Red Hat OpenStack Platform, and Red Hat Virtualization.

Please ensure that the underlying Red Hat Enterprise Linux kernel is current in these product environments.

Mitigation

Overall Guidance

Red Hat is currently investigating mitigation options. Detailed guidance will be provided in a future update to this bulletin.

Updates for Affected Products

Red Hat customers running affected versions of these Red Hat products are strongly recommended to update as soon as erratas are available. Customers are urged to apply the available updates immediately and enable the mitigations as they feel appropriate.

Was this information helpful? Your feedback is valuable!

Feedback cancelled

Comments