Fifteen years hidden, then an AI found it

Nebula Security's AI platform VEGA just surfaced GhostLock — a use-after-free in the Linux kernel's futex implementation that's been sitting in the source tree since 2.6.39 shipped in 2011. The bug gives any unprivileged local user root in roughly five seconds, with a reported 97% success rate on vulnerable systems. That isn't a "tools are getting better" anecdote. It's a measurable shift in what kind of bug is findable, and the receipt is a CVE.

The thesis: AI-assisted review is now catching kernel bugs that fifteen years of human review didn't. If your security story relies on "we read the code," this is the slide that makes you update it.

[[CHART: the 15-year window from kernel 2.6.39 release (2011) to GhostLock disclosure (2026), with exploit timing shown as a tiny slice at the end]]

What GhostLock actually is