If you're just now hearing about GhostLock and looking to fix it, make sure you don't introduce two unpriv-reachable DoSes associated with its fixes. The fix the Linux CNA lists for CVE-2026-43499 introduces a NULL deref, which caused CVE-2026-53166 to be issued.
Unfortunately, the fix referenced by that CVE introduces a worse DoS (busy loops on all CPUs in the kernel), and has no CVE yet to inform users. We discovered this second DoS early last month through routine inspection.
Our recommendation:
Apply the initial fix:
https://git.kernel.org/pub/scm/linux/
kernel/git/torvalds/linux.git/commit/?id=3bfdc63936dd4773109b7b8c280c0f3b5ae7d349
Ignore the fix for CVE-2026-53166 which introduced the worse DoS and was reverted just recently:
https://git.kernel.org/pub/scm/linux/
kernel/git/torvalds/linux.git/commit/?id=39def6d250d370298f86c116f4ac60093cefadaa
Apply this fix which addressed the same initial DoS issue without introducing another:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=40a25d59e85b3c8709ac2424d44f65610467871e