CVE-2026-43499, known as "GhostLock", is a High-severity (CVSS 7.8) Use-After-Free (UAF) vulnerability in the Linux kernel's real-time mutex (rtmutex) and priority-inheritance (PI) futex code.
As BOSH stemcells are currently using Jammy, this vulnerability is present. It's valuable to note that this is a local privilege escalation instead of a remote code execution issue.
More details on this CVE are available here:
BOSH stemcells
This has been fixed with Jammy Stemcell 1.1364