CVE-2026-43499 impact on BOSH stemcells
search cancel

CVE-2026-43499 impact on BOSH stemcells

book

Article ID: 448780

calendar_today

Updated On:

Products

VMware Tanzu Kubernetes Grid Integrated Edition Operations Manager

Issue/Introduction

CVE-2026-43499, known as "GhostLock",  is a High-severity (CVSS 7.8) Use-After-Free (UAF) vulnerability in the Linux kernel's real-time mutex (rtmutex) and priority-inheritance (PI) futex code.

As BOSH stemcells are currently using Jammy, this vulnerability is present. It's valuable to note that this is a local privilege escalation instead of a remote code execution issue.

More details on this CVE are available here:


https://ubuntu.com/security/CVE-2026-43499

https://nvd.nist.gov/vuln/detail/CVE-2026-43499

Environment

BOSH stemcells

Resolution

This has been fixed with Jammy Stemcell 1.1364

https://techdocs.broadcom.com/us/en/vmware-tanzu/platform/stemcells/services/stemcell-rn/stemcells.html#1.1364