Two Linux kernel use-after-free vulnerabilities were disclosed in packet-filtering components, exposing systems to local privilege escalation. CVE-2026-23111 affects the nftables subsystem and stems from an inverted conditional in nft_map_catchall_activate() that mishandles catchall elements during transaction aborts, leaving a dangling chain reference. A public technical write-up and working exploit showed the bug can achieve root privileges with high reliability on Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS by corrupting chain reference counts, bypassing KASLR, leaking heap addresses, hijacking control flow with a fake nft_expr_ops structure, and executing a ROP chain that calls commit_creds(&init_cred). The exploit also uses switch_task_namespaces() to break out of namespaces and containers.
A separate flaw, CVE-2026-23412, affects the Linux kernel’s BPF netfilter link implementation in nf_bpf_link.c, where synchronous deallocation of bpf_nf_link_lops allowed concurrent nfnetlink hook enumeration to access freed memory during BPF link destruction. Researchers reproduced KASAN slab-use-after-free crashes in nfnl_hook_dump_one on kernel 6.14.0 and said the bug could be exploited through heap spraying and function-pointer hijacking in the kmalloc-192 slab cache. The issue was introduced in 6.4-rc1 and fixed in 7.0-rc5 by commit 24f90fa3994b, which switches to RCU-deferred freeing, while the nftables bug was patched upstream by commit f41c5d1; administrators were urged to deploy patched kernels promptly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The new report states that testing confirmed CVE-2026-23111 affects RHEL 10 in addition to previously reported Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS systems. The article also notes Ubuntu and Debian have issued patches while other vendors are tracking the flaw.
The reference states that FuzzingLabs published a reproduction of the CVE-2026-23111 exploit in April 2026, making exploit details publicly available before the later June 8 technical walkthrough by Exodus Intelligence. This represents an earlier public technical disclosure related to the flaw.
CVE-2026-23111 was publicly disclosed with a technical write-up and working exploit demonstrating root privilege escalation and namespace breakout. The disclosure reported impact on Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
Oliver Sieber of Exodus Intelligence discovered a local privilege escalation vulnerability in the Linux kernel nftables subsystem in early 2025. The bug is a use-after-free tied to mishandling of catchall elements during transaction aborts.
Aretiq AI published research describing CVE-2026-23412 as a Linux kernel local privilege escalation vulnerability affecting the BPF netfilter link implementation. The write-up said the issue was reproducible on kernel 6.14.0 and exploitable via heap spraying and function pointer hijacking.
A use-after-free flaw in the Linux kernel's BPF netfilter link implementation, tracked as CVE-2026-23412, was fixed in kernel 7.0-rc5 by commit 24f90fa3994b. The change deferred freeing with RCU to prevent concurrent hook enumeration from accessing freed memory.
The Linux kernel upstream patched CVE-2026-23111 on 2026-02-05. The fix is identified as commit f41c5d1, and administrators were advised to deploy patched kernels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityaffairs.com
Open sourcethecybersecguru.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcearetiq.ai
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.