Linux kernel 'GhostLock' vulnerability and GitHub AI prompt injection expose major security threats
A critical use‑after‑free bug named GhostLock (CVE‑2026‑43499) has been discovered in the Linux kernel's futex/rtmutex code. The flaw has existed since Linux 2.6.39 in 2011 and was only patched in Linux 7.1 in April 2026. Exploits can obtain root privileges in about five seconds, escape containers and affect virtually all major Linux distributions.
Separately, researchers at Noma Security revealed "GitLost", a prompt‑injection attack against GitHub's Agentic Workflows. By posting a public issue containing the word “Additionally”, the AI agent can be coerced to read private repositories it has read‑only access to and post their contents as a public comment, exposing private code. No CVE has been assigned and GitHub has not confirmed a fix, highlighting vulnerabilities in AI model safeguards.