{"id":182595,"date":"2026-07-10T22:54:14","date_gmt":"2026-07-10T20:54:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup"},"modified":"2026-07-10T22:54:14","modified_gmt":"2026-07-10T20:54:14","slug":"v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup","title":{"rendered":"In Linux \u00e8 stata scoperta una vulnerabilit\u00e0 GhostLock che consente di ottenere accesso root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex>          <a rel=\"nofollow\" id=\"memories_button\" href=\"#\" title=\"Monitorare\"><i class=\"icon-bell\"><\/i><\/a><br \/>1                            <noindex><\/p>\n<p>Una vulnerabilit\u00e0 \u00e8 stata scoperta nel kernel Linux <a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43499\">CVE-2026-43499<\/a>, soprannominata in modo non ufficiale GhostLock. Il problema riguarda il codice rtmutex e il meccanismo futex con eredit\u00e0 di priorit\u00e0, e sfruttarla potrebbe consentire a un utente locale non privilegiato di elevare i diritti a root. Secondo <a rel=\"nofollow\" href=\"https:\/\/almalinux.org\/cs\/blog\/2026-07-09-ghostlock\/\">AlmaLinux<\/a>, la vulnerabilit\u00e0 potrebbe essere utilizzata anche da un container per uscire sul host, se il sistema gira su un kernel non aggiornato.<\/p>\n<p><\/noindex>  <noindex><\/p>\n<p>La natura dell'errore \u00e8 collegata alla funzione remove_waiter() in kernel\/locking\/rtmutex.c. Come indicato in <a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43499\">una descrizione NVD<\/a>, durante il rollback di proxy-lock nello scenario futex_requeue(), la funzione operava con il task attuale (current), mentre avrebbe dovuto ripulire lo stato del task che stava realmente aspettando la lock (waiter::task). Di conseguenza, lo stato pi_blocked_on potrebbe non essere stato pulito correttamente, lasciando un puntatore pendente e creando le premesse per un use-after-free.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>I ricercatori di Nebula Security <a rel=\"nofollow\" href=\"https:\/\/nebusec.ai\/research\/ionstack-part-2\/\">hanno descritto GhostLock<\/a> come un errore presente nelle principali distribuzioni di Linux dal 2011. La discussione pubblica sulla vulnerabilit\u00e0 ha aumentato il rischio per server ed ambienti containerizzati: <a rel=\"nofollow\" href=\"https:\/\/blog.cloudlinux.com\/ghostlock-cve-2026-43499-local-root-exploit-kernel-update-for-cloudlinux\/\">CloudLinux<\/a> avverte separatamente che per CVE-2026-43499 esiste gi\u00e0 una prova di concetto pubblica, pertanto gli amministratori non dovrebbero rimandare l'aggiornamento del kernel.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>La correzione upstream implica che remove_waiter() debba utilizzare waiter::task, e non current, in tutte le operazioni correlate. Questo \u00e8 indicato anche da <a rel=\"nofollow\" href=\"https:\/\/github.com\/advisories\/GHSA-cqc6-9f34-295v\">GitHub Advisory Database<\/a>, dove vengono elencate le conseguenze dell'errore: rimozione errata da rbtree senza la necessaria lock, stato pi_blocked_on non pulito e funzionamento di rt_mutex_adjust_prio_chain() non con il task corretto.<\/p>\n<p><\/noindex> <\/p>\n<p>Si raccomanda agli utenti delle distribuzioni Linux di installare gli aggiornamenti del kernel pi\u00f9 recenti dai repository ufficiali. La vulnerabilit\u00e0 \u00e8 di natura locale, quindi di per s\u00e9 non consente un accesso remoto, ma nei server multi-utenza, nelle infrastrutture CI, nell'hosting e nei sistemi con container il rischio \u00e8 notevolmente pi\u00f9 elevato: uno sfruttamento riuscito trasforma gi\u00e0 l'accesso con privilegi bassi in un controllo completo del sistema.<\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18336500\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>1 \u0412 \u044f\u0434\u0440\u0435 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c CVE-2026-43499, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0430\u044f \u043d\u0435\u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0435 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 GhostLock. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043a\u043e\u0434 rtmutex \u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c futex \u0441 \u043d\u0430\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0440\u0438\u043e\u0440\u0438\u0442\u0435\u0442\u0430, \u0430 \u0435\u0451 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442\u044c \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 \u0434\u043e root. \u041f\u043e \u0434\u0430\u043d\u043d\u044b\u043c AlmaLinux, \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 \u0434\u043b\u044f \u0432\u044b\u0445\u043e\u0434\u0430 \u043d\u0430 \u0445\u043e\u0441\u0442, \u0435\u0441\u043b\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043d\u0430 \u043d\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0451\u043d\u043d\u043e\u043c \u044f\u0434\u0440\u0435. \u0421\u0443\u0442\u044c \u043e\u0448\u0438\u0431\u043a\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182595","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"1 \u0412 \u044f\u0434\u0440\u0435 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Emin Berklin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c GhostLock, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"1 \u0412 \u044f\u0434\u0440\u0435 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-10T20:54:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-10T20:54:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47In Linux \u00e8 stata scoperta la vulnerabilit\u00e0 GhostLock, che consente di ottenere accesso root | ProHoster","description":"1 Una vulnerabilit\u00e0 \u00e8 stata scoperta nel kernel Linux","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c GhostLock, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f | ProHoster","og:description":"1 \u0412 \u044f\u0434\u0440\u0435 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/v-linux-raskryta-uyazvimost-ghostlock-pozvolyayushhaya-poluchit-root-dostup","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-07-10T20:54:14+00:00","article:modified_time":"2026-07-10T20:54:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182595","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-05 12:22:05","updated":"2026-08-05 12:22:05","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182595","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=182595"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182595\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=182595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=182595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=182595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}