CVE-2026-23231 is a use-after-free vulnerability in the Linux kernel Netfilter nftables subsystem. nf_tables_addchain() publishes a new chain through an RCU-protected table chain list before hook registration completes. If hook registration subsequently fails, its error path removes the chain and destroys it without waiting for an RCU grace period. Concurrent control-plane chain dumps can retain a reference while traversing the RCU-protected list. In the NFPROTO_INET case, IPv4 hook installation can transiently succeed before IPv6 registration fails, allowing in-flight packets to enter nft_do_chain() and dereference chain state after the chain has been freed. The fix waits for an RCU grace period after chain deletion and before destruction, ensuring that dump readers and packet-processing readers have completed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
Unknown
A Linux kernel use-after-free vulnerability in nf_tables_addchain() that may allow privilege escalation or denial of service.
A Linux kernel netfilter nf_tables use-after-free vulnerability in nf_tables_addchain() caused by freeing a chain after list removal without an RCU grace period when hook registration fails.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.