A Linux privilege-escalation flaw tied to CVE-2026-43499 shows how a small mistake in lock state tracking can turn into a serious host-level security problem.