CVE-2026-43499
In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.77% chance of exploitation in the next 30 days, 53th percentile
- Published
- 2026-05-21
- Updated
- 2026-08-26
Proof-of-concept exploits (109)
- MobiusM/CVE-2026-43499154★ · 2026-06-27
- x-spy/CVE-2026-43499-popsicle235★ · 2026-07-15
- alex193a/Root-My-Pixel236★ · 2026-08-31
- xianwan1314/CVE-2026-43499-Poc-Analysis18★ · 2026-07-14
- Linuxoid-cn/CVE-2026-43499-Poc-Analysis80★ · 2026-07-30
- pubglite55/oppo-ghostlock62★ · 2026-08-08
- CakesTwix/Android-CVE-2026-4349963★ · 2026-07-20
- BuSung-dev/CVE-2026-43499-S25U42★ · 2026-07-17
- Colorful-glassblock/duchamp-root50★ · 2026-07-31
- woshimaniubi8/CVE-2026-43499-root-KernelSU25★ · 2026-07-26
- boxiaolanya2008/CVE-2026-43499-Neo11Plus23★ · 2026-08-28
- gagaltotal/CVE-2026-43499-PoC-Scanner17★ · 2026-07-22
- WitAqua-tools/Root-My-Device12★ · 2026-08-29
- tc3650/CVE-2026-43499-armv79★ · 2026-07-27
- p2p3p/GhostLock-for-OnePlus41★ · 2026-07-19
- Bartixxx32/CVE-2026-43499-OnePlus158★ · 2026-07-14
- Bailan766/rmx3888-cve-2026-43499-config6★ · 2026-07-24
- joehquak/Mi8E5-Unlocker-by-CVE-2026-434997★ · 2026-07-14
- 1ndevelopment/CVE-2026-43499-S267★ · 2026-08-19
- No-22-Github/UnPlus7★ · 2026-08-08
- soralis0912/CVE-2026-43499-aristotle-apk5★ · 2026-07-25
- Wtrwx/smt878u-ionstack-poc10★ · 2026-07-21
- 0xBlackash/CVE-2026-434998★ · 2026-07-10
- sorrow404Null/CVE-2026-43499-RMX52006★ · 2026-07-17
- soralis0912/CVE-2026-43499-aristotle4★ · 2026-07-24
- fusiondrive/CVE-2026-43499-S24U4★ · 2026-08-11
- Petalrain224/CVE-2026-43499-Redmi-Turbo54★ · 2026-08-02
- NothingFumo/ghostlock-aresin5★ · 2026-08-15
- Thiasap/oppo-pgem10-ghostlock5★ · 2026-07-13
- cuteaplane/GhostLock-for-OnePlus15T17★ · 2026-07-25
- virtualesp/SpringPeace0★ · 2026-07-13
- 233laoliu/mt6985-CVE-2026-434992★ · 2026-07-31
- soralis0912/CVE-2026-43499-pmg110-root2★ · 2026-07-27
- qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-434992★ · 2026-08-22
- HORKimhab/CVE-2026-434990★ · 2026-07-08
- caspy123/CVE-2026-434990★ · 2026-07-10
- CatXiaoShi/cve-2026-434990★ · 2026-08-04
- MiaPatsune/cve-2026-434991★ · 2026-07-17
- dnlid/CVE-2026-434991★ · 2026-07-27
- onesmiledx/CVE-2026-434991★ · 2026-07-15
- justsoman/CVE-2026-43499-jinghu0★ · 2026-07-16
- fusiondrive/CVE-2026-43499-A361★ · 2026-08-01
- soralis0912/CVE-2026-43499-warhol-root1★ · 2026-07-26
- inforcqb/CVE-2026-43499-pja1101★ · 2026-07-10
- Cxyofficial/x200-cve-2026-434990★ · 2026-07-26
- ctn-Qvo/CVE-2026-43499-so-build1★ · 2026-07-15
- mumaosong/cve-2026-43499-CyberMeowfia1★ · 2026-07-24
- HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-434991★ · 2026-07-15
- Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall1★ · 2026-07-18
- sarabpal-dev/IonStack-S22U61★ · 2026-08-28
- mobilehackinglab/ghostlock-a1711★ · 2026-08-21
- snothin/ghostlock-s2611★ · 2026-08-24
- R0rt1z2/GhostLock-5.1016★ · 2026-08-21
- NanoTurtle1145/root-my-s2428★ · 2026-08-27
- yakidango-official/GhostLock-H80GT6★ · 2026-08-29
- yijiacloud/ghostlock-cve-2026-43499-4.19-k408★ · 2026-08-12
- eroorvbsyes-hotmail/CVE-2026-43499_x86_Exploit3★ · 2026-08-04
- Bugel/cve-2026-43499-m3q-azf13★ · 2026-08-14
- zzzxxxxxxxxxx/GhostLock-GOT-W293★ · 2026-08-30
- gitchw/ghostlock-cve-2026-434990★ · 2026-08-22
- pimpamebanihah/cve-2026-43499-app.so0★ · 2026-08-13
- fusiondrive/CVE-2026-43499-ZFOLD40★ · 2026-08-15
- xrzcc/s26-m1q-ghostlock-selinux4★ · 2026-08-21
- pimpamebanihah/cve-2026-43499-app.s00★ · 2026-08-13
- Redminote11tech/CVE-2026-43499-NAM-AL001★ · 2026-08-24
- yijiacloud/GhostLock-OPPO-PCKM003★ · 2026-08-11
- jason5545/ghostlock-myron-tw3★ · 2026-08-03
- ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock7★ · 2026-08-23
- wzhdgithub/GhostLock3★ · 2026-08-13
- Cxyofficial/k50g-pocof4gt-cve-2026-43499-test0★ · 2026-08-25
- E-R-Butch/F9360-CVE434994★ · 2026-08-12
- hackyangwen-lgtm/rmg-s9180-fzg12★ · 2026-08-27
- zenyxx-xd/RootMyVivo1★ · 2026-08-29
- wfqefwqf/share-poc-XRing-O10★ · 2026-07-19
- BuSung-dev/Root-My-Galaxy-Payloads348★ · 2026-08-25
- WitAqua-tools/Root-My-Device-Payloads8★ · 2026-08-29
- Sulisong/violin-6.6.77-POC0★ · 2026-07-17
- crabcakes97/GhostLock-Nevada1★ · 2026-08-09
- hdoublearp/Root-My-Galaxy-Payloads0★ · 2026-08-04
- Memetic0/Root-My-Galaxy-Payloads0★ · 2026-08-18
- debug-deng/F956B-Payload0★ · 2026-08-17
- MidPanda/GhostLock-for-PKJ1101★ · 2026-08-21
- JackKnifeAI/S25-Ultra-Root4★ · 2026-08-28
- Te-River/SukiSU_SUSFS-Kernel0★ · 2026-08-28
- BailinT/GKI_KernelSU_SUSFS-hwid0★ · 2026-08-29
- qianmingzi7-coder/tb322fc-r2-kernel-public-build0★ · 2026-08-28
- PuceLi/GKI_KernelSU_SUSFS_Local0★ · 2026-08-26
- jojobear691/SM-A166W-DZG1-Temporary-Root1★ · 2026-08-27
- wandawrt01/Root-My-Pixel0★ · 2026-08-28
- Kelsidavis/lg-g710tm-unlock0★ · 2026-08-27
- ReBiliBin/ghostlock-oppo-watch3pro1★ · 2026-08-30
- caramel1205zh/GKI_KernelSU_SUSFS0★ · 2026-08-30
- realthotboyshit/sukisu-0★ · 2026-08-29
- cancelledbit/x9u-501-unlock-kit0★ · 2026-08-29
- Alfnnnnyy/GKI_KernelSU_SUSFS0★ · 2026-08-31
- a15831536502-del/GKI_KernelSU_SUSFS
- N1et/samsung-m53-root-4x
- zenyxx-xd/RootMyVivo-Payloads
- 2932796375github/CVE-2026-43499_OPPO-MT6835
- fancyzll/CVE-2026-43499_OPPO-MT6835
- knowlily/cve-2026-43499-honor
- zychen027/CVE-2026-43499_HW-CLT-AL01
- Cxyofficial/k50g-pocof4gt-cve-2026-43499-poc
- DurkaEbanaya/Root-My-Pixel-Pixel6a
- L-CharMing/Root-My-Galaxy-Payloads-S23
- abdgalaxy36-code/Root-My-Galaxy-Payloads-A37-Clean
- d1667018881/myroot
- hasan-khalil/root-acccess-lib
- lkeld/CVE-2026-43499-poc