AI Unveils 15-Year-Old Linux Kernel Root Vulnerability
Fifteen years hidden, then an AI found it
Nebula Security's AI platform VEGA just surfaced GhostLock — a use-after-free in the Linux kernel's futex implementation that's been sitting in the source tree since 2.6.39 shipped in 2011. The bug gives any unprivileged local user root in roughly five seconds, with a reported 97% success rate on vulnerable systems. That isn't a "tools are getting better" anecdote. It's a measurable shift in what kind of bug is findable, and the receipt is a CVE.
The thesis: AI-assisted review is now catching kernel bugs that fifteen years of human review didn't. If your security story relies on "we read the code," this is the slide that makes you update it.
This is an excerpt. Read the full post at otf-kit.dev/blog/linux-kernel-ghostlock — full-stack kits your AI coding agent can actually ship to production. Browse the kits →
Ship the product, not the setup.
- 11 production screens — auth, billing, team, analytics, settings
- Real database, payments, and login — all wired on day 1
- AI configs pre-tuned so your agent extends instead of regenerates