[Notice] Mitigation for GhostLock (CVE-2026-43499) Completed

A local privilege escalation vulnerability in the Linux kernel, GhostLock (CVE-2026-43499), has been disclosed.

To address this vulnerability, PFCP completed emergency maintenance on July 23, 2026, during which we updated the Linux kernel on the host operating system of PFCP-managed Kubernetes nodes.

Mitigation

The Linux kernel on the host operating system (Ubuntu 24.04 LTS) of PFCP-managed Kubernetes nodes has been updated to 6.8.0-136.136, which addresses GhostLock (CVE-2026-43499).

Completion Time

July 23, 2026, 12:00 JST

Customer Action Required

No action is required from PFCP users.

For details of the maintenance associated with this update, please refer to the following announcement.

References


PFCP is committed to providing timely security updates so that our users can continue to use our services with confidence.