CVE-2026-23111Disclosure(linux / linux_kernel)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 28 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don't need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones. Compare the non-catchall activate callback, which is correct: nft_mapelem_activate(): if (nft_set_elem_active(ext, iter->genmask)) return 0; /* skip active, process inactive */ With the buggy catchall version: nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */ The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain->use reference count. Each abort cycle permanently decrements chain->use. Once chain->use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free. This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES. Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-672

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 88 mentions across 25 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 15 signals
  • PoC mentioned or linked in 35 signals
  • Patch or workaround mentioned in 32 signals
  • Technical details provided in 67 signals
  • Disclosure: 28 classified signals
  • General: 14 classified signals
  • Peaked 20d ago at 28 mentions (2026-06-09); latest day: 1
  • 88 total mentions across 25 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline88 mentions / 25d
07142128Mentions · 2026-02-13: 1Mentions · 2026-02-27: 1Mentions · 2026-04-16: 1Mentions · 2026-06-08: 9Mentions · 2026-06-09: 28Mentions · 2026-06-10: 13Mentions · 2026-06-11: 8Mentions · 2026-06-12: 5Mentions · 2026-06-13: 1Mentions · 2026-06-15: 1Mentions · 2026-06-17: 1Mentions · 2026-06-18: 3Mentions · 2026-06-19: 1Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Mentions · 2026-06-27: 2Mentions · 2026-06-29: 1Mentions · 2026-07-05: 1Mentions · 2026-07-07: 1Mentions · 2026-07-10: 1Mentions · 2026-07-17: 1Mentions · 2026-08-24: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 2Mentions · 2026-10-05: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-06-08: 4PoC Mentioned / Linked · 2026-06-09: 12PoC Mentioned / Linked · 2026-06-10: 2PoC Mentioned / Linked · 2026-06-11: 4PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-06-13: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-06-18: 1PoC Mentioned / Linked · 2026-06-25: 2PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-27: 2PoC Mentioned / Linked · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-06-08: 1Exploit Tool / Code · 2026-06-09: 5Exploit Tool / Code · 2026-06-10: 1Exploit Tool / Code · 2026-06-11: 2Exploit Tool / Code · 2026-06-13: 1Exploit Tool / Code · 2026-06-17: 1Exploit Tool / Code · 2026-06-18: 1Exploit Tool / Code · 2026-06-26: 1Exploit Tool / Code · 2026-06-27: 1Exploit Tool / Code · 2026-08-24: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-09: 2Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-12: 1Patch / Workaround · 2026-06-08: 6Patch / Workaround · 2026-06-09: 11Patch / Workaround · 2026-06-10: 6Patch / Workaround · 2026-06-11: 4Patch / Workaround · 2026-06-12: 2Patch / Workaround · 2026-06-25: 2Patch / Workaround · 2026-06-27: 1Technical Details · 2026-02-13: 1Technical Details · 2026-04-16: 1Technical Details · 2026-06-08: 9Technical Details · 2026-06-09: 21Technical Details · 2026-06-10: 10Technical Details · 2026-06-11: 5Technical Details · 2026-06-12: 3Technical Details · 2026-06-13: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-18: 3Technical Details · 2026-06-19: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 202-1304-1606-0906-1106-1306-1706-1906-2606-2907-0707-1708-2710-05
Signal classification6 categories
Disclosure
2832.2%
Exploit
1921.8%
General
1416.1%
Patch
1112.6%
PoC
1011.5%
Active Exploitation
55.7%
Referenced assets55 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-131
Disclosure1
2026-02-271
General1
2026-04-161
Disclosure1
2026-06-089
Active Exploitation1Disclosure2Exploit4Patch1PoC1
2026-06-0928
Active Exploitation2Disclosure6Exploit5General6Patch5PoC4
2026-06-1013
Active Exploitation1Disclosure6Exploit2General1Patch3
2026-06-118
Disclosure3Exploit4Patch1
2026-06-125
Active Exploitation1Disclosure2General1Patch1
2026-06-131
Exploit1
2026-06-151
PoC1
2026-06-171
Exploit1
2026-06-183
Disclosure1Exploit1General1
2026-06-191
Disclosure1
2026-06-252
PoC2
2026-06-261
PoC1
2026-06-272
Exploit1General1
2026-06-291
General1
2026-07-051
Disclosure1
2026-07-071
General1
2026-07-101
General1
2026-07-171
Disclosure1
2026-08-241
Disclosure1
2026-08-271
PoC1
2026-08-282
Disclosure2
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Exploit

    🚨 A single stray "!" in the #Linux kernel's firewall code (nftables). That one character let any normal logged-in user become root, and step out of the container. The fix? One line. And the exploit (CVE-2026-23111) to abuse it just went public. Read: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html

    Post summary

    A single stray character in the Linux nftables firewall code creates a privilege escalation that’s now exposed via a publicly released exploit, while a one‑line patch is available to mitigate the flaw.

    597835413135.5K
    2.0M followersView on X
  • I'M H4CK3R 42@luckyhacker43
    PoC

    [CVE-2026-23111] A missing “!” in Linux kernel code leads to full root compromise 👾💥 🔗 https://fuzzinglabs.com/repro-cve-2026-23111/ 🔗 https://t.me/luckyhacker42 https://t.co/spmiUEp7QV

    Post summary

    The post announces CVE‑2026‑23111, explains that a missing exclamation mark in Linux kernel code leads to root compromise, and provides a link to a reproducible proof‑of‑concept.

    1151115716.9K
    5.0K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Nueva vulnerabilidad de Linux permite escalar privilegios a root Se ha revelado una vulnerabilidad de tipo use-after-free en el subsistema nftables del kernel de Linux, identificada como CVE-2026-23111 https://blog.elhacker.net/2026/06/nueva-vulnerabilidad-de-linux-permite.html

    Post summary

    A new use‑after‑free vulnerability (CVE-2026-23111) in the Linux nftables kernel subsystem has been disclosed, but no PoC, exploit, active exploitation, patch, or debunking information is provided.

    2310106465.6K
    141.0K followersView on X
  • The Hacker News@TheHackersNews
    Exploit

    This is the kind of Linux bug attackers love. > Not remote > Not flashy > Easy to miss But once they already have a small foothold, it can turn that access into full control of the host. CVE-2026-23111 now has public exploit details. Patch + reboot: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html https://t.co/bKrv66Opb5

    Post summary

    The post announces that CVE-2026-23111 has publicly available exploit details and recommends a patch with reboot, but it does not provide a specific exploit tool, evidence of active attacks, or technical vulnerability specifics.

    62901113419.3K
    2.0M followersView on X
  • I'M H4CK3R 42@luckyhacker43

    one missing ! → root. 💀 Body: CVE-2026-23111 // nf_tables UAF inverted check → catchall skip on abort → chain->use-- every abort → hits 0 → freed while live → UAF → ROP → root LPE. container escape. >99% reliable. Debian, Ubuntu, RHEL, SUSE hit. patch + reboot or get pwned. 🔗 http://fuzzinglabs.com/repro-cve-2026-23111/ 👉 http://t.me/luckyhacker42 #Linux #CVE #LPE #0day

    0140107547.4K
    5.0K followersView on X
  • Linux Kernel Security@linkersec
    PoC

    Off By !: Exploiting a Use-after-Free in the Linux Kernel Oliver Sieber published write-up on CVE-2026-23111 in nftables, found in early 2025, patched upstream by other researchers in Feb 2026. Article describes exploiting this UAF on Debian and Ubuntu. https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/

    Post summary

    The post announces a write‑up of a use‑after‑free vulnerability in nftables (CVE‑2026‑23111) with a PoC, notes the discovery was patched, but no active exploitation or detailed exploit tool is disclosed.

    014077594.7K
    10.5K followersView on X
  • FuzzingLabs@FuzzingLabs
    Disclosure

    We reproduced and analyzed CVE-2026-23111, a Linux kernel vulnerability in nftables that led to a use-after-free which we leveraged to achieve local privilege escalation. Full write-up: https://fuzzinglabs.com/repro-cve-2026-23111/ https://t.co/8OEKK3FG3g

    Post summary

    The post documents the reproduction and analysis of CVE‑2026‑23111, a Linux kernel use‑after‑free in nftables that can lead to local privilege escalation, and links to a write‑up containing technical details.

    218061314.2K
    9.1K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    Disclosure

    [CVE-2026-23111] A missing “!” in Linux kernel code leads to full root compromise 👾💥 🔗 https://fuzzinglabs.com/repro-cve-2026-23111/ 🔗 https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html 🔗 https://cybersecuritynews.com/linux-kernel-nftables-vulnerability/ 👉 http://t.me/luckyhacker42 https://t.co/8JfgBt6U95

    Post summary

    CVE‑2026‑23111 is a newly disclosed Linux kernel flaw where a missing exclamation mark can lead to full root compromise; proof of concept links are provided, but no active exploitation, patch, or debunking information is present.

    0803092.8K
    5.0K followersView on X
  • dbugs@ptdbugs
    PoC

    Linux Kernel nf_tables Use-After-Free Vulnerability CVE: CVE-2026-23111 PT ID: PT-2026-7991 Vendor: Linux Product: Linux CVSS: 7.8 Credits: n/a Description: A use-after-free issue exists in the "nf tables" component of the Linux kernel. The function "nft map catchall activate()" contains an inverted element activity check compared to the logically required behavior and its counterpart "nft mapelem activate()". Specifically, the function incorrectly skips inactive elements and processes active ones during the abort path used to re-activate catchall map elements after a failed transaction. When a "DELSET" operation is aborted, "nft setelem data activate()" is not called for the catchall element. For "NFT GOTO" verdict elements, this prevents "nft data hold()" from restoring the "chain->use" reference count. Repeated abort cycles permanently decrement "chain->use" until it reaches zero, allowing a "DELCHAIN" operation to free the chain while catchall verdict elements still reference it. This can be exploited by an unprivileged local user to achieve local privilege escalation to root and escape containers on distributions where "CONFIG USER NS" and "CONFIG NF TABLES" are enabled. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-23111 • https://git.kernel.org/stable/c/8c760ba4e36c750379d13569f23f5a6e185333f5 PoC/Exploit: https://github.com/Baba01hacker666/CVE-2026-23111 #dbugs_vuln

    Post summary

    A locally exploitable use‑after‑free in Linux nf_tables is disclosed with technical details and a linked PoC/Exploit repository, but no evidence of live exploitation or patch availability.

    2602751.4K
    3.0K followersView on X
  • yousukezan@yousukezan
    Exploit

    Linuxカーネルのnftablesに存在したCVE-2026-23111は、たった1文字の条件分岐ミスが原因で、一般ユーザーやコンテナ内の攻撃者がroot権限を取得できる深刻なローカル権限昇格(LPE)脆弱性だった。 問題は、トランザクションのロールバック処理で本来有効化すべき要素を誤って無効のまま残してしまう実装ミスにある。この結果、参照カウント管理が破綻し、解放済みメモリを参照するUse-After-Free(UAF)が発生する。攻撃者はこれを利用してカーネルメモリを操作し、権限昇格やコンテナ脱出を実現できる。 Exodus Intelligenceは2026年6月に詳細な解析と実証コードを公開。アイドル環境で99%以上、高負荷環境でも約80%の成功率を示した。攻撃ではKASLR回避、ヒープアドレス漏えい、ROPチェーンによる制御フロー乗っ取りを組み合わせ、最終的にroot権限とホスト名前空間へのアクセスを獲得する。 影響を受けるのはUbuntu、Debian、RHELなど複数の主要ディストリビューションで、未特権ユーザー名前空間(User Namespace)が有効な環境ほどリスクが高い。 各ベンダーから更新版カーネルも提供済みだが、適用には再起動が必要となる。記事は、未特権ユーザー名前空間の無効化やnf_tablesモジュールの無効化を一時的な緩和策として挙げつつ、根本的な対策はパッチ適用であると強調している。 https://thecybersecguru.com/news/cve-2026-23111-linux-kernel-nftables-privilege-escalation/

    Post summary

    CVE‑2026‑23111 is a local privilege escalation in Linux nftables; a proof‑of‑concept exploit with high success rates has been released, and vendors have issued kernel patches with temporary mitigations advised.

    07117112.0K
    14.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Critical Linux kernel use-after-free in nftables enables unprivileged local privilege escalation to root. CVE-2026-23111 affects major distributions including Debian and Ubuntu systems. Technical details: • Flaw in nft_map_catchall_activate() function incorrectly skips deactivated catchall elements during abort process • Vulnerability triggered via crafted netlink batches: delete pipapo set → force abort → toggle generation → delete set → delete chain • Results in chain reference counter reaching zero while valid references remain, creating exploitable use-after-free • Affects nftables subsystem generation mask handling and catchall element lifecycle management Attack methodology: • Requires unprivileged user namespace creation (bypassable on Ubuntu 24.04 via aa-exec) • Multi-stage exploit: trigger vulnerability → leak kernel base (defeat KASLR) → leak heap addresses → ROP chain execution • Achieves privilege escalation via commit_creds(&init_cred) and namespace escape through switch_task_namespaces() • Stability >99% on idle systems, drops to 80% under load Impact spans Debian Bookworm/Trixie and Ubuntu 22.04/24.04 LTS. Patch applied February 2026. Hunt for suspicious nftables operations with pipapo sets and generation cursor manipulation in audit logs. #DFIR_Radar

    Post summary

    The post discloses a critical Linux kernel use‑after‑free in nftables, provides detailed exploitation steps, notes a patch timeline, and advises defenders to monitor suspicious nftables activity.

    1301511.0K
    1.8K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    General

    CVE-2026-23111: Linux nf_tables Flaw Enables Root Exploits https://securityaffairs.com/193352/hacking/cve-2026-23111-linux-nf_tables-flaw-enables-root-exploits.html

    Post summary

    The article announces a Linux nf_tables flaw that permits root privilege escalation, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    03094649
    18.1K followersView on X
  • [email protected] / EDRmetry / PurpleLabs@cr0nym
    General

    Detecting the nftables Catchall Use-After-Free (CVE-2026–23111) by thinking outside the box - Authored by Rafael David Tinoco https://medium.com/@miggo-engineering/detecting-the-nftables-catchall-use-after-free-cve-2026-23111-by-thinking-outside-the-box-2227654d5acf

    Post summary

    The Medium article discusses detecting the nftables Catchall Use-After-Free (CVE-2026‑23111) but provides no PoC, exploit, patch, or active exploitation details.

    010851.0K
    3.2K followersView on X
  • AlexAImaginator@TraffAlex
    Exploit

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — June 11, 2026 1️⃣ LINUX KERNEL PRIVILEGE ESCALATION BUG GETS PUBLIC EXPLOIT — CVE-2026-23111 A Linux kernel vulnerability rated as a favorite among attackers has gone public. CVE-2026-23111 is neither remote nor flashy, which makes it easy to overlook — but once an adversary has a small foothold on a system, this flaw can be leveraged to escalate to full host control. Public exploit code is now circulating, meaning any unpatched machine is sitting duck territory. The fix is straightforward: patch the kernel and reboot, but the window between disclosure and widespread patching is where the real damage happens. @TheHackersNews 2️⃣ VERTIV DATA CENTER GEAR HIT WITH TWO CRITICAL CVEs Critical infrastructure is in the crosshairs. Claroty's Team82 lab identified two vulnerabilities — CVE-2025-41426 and CVE-2025-46412 — in Vertiv's Liebert RDU101 and Liebert UNITY products. Both flaws allow arbitrary code execution and authentication bypass on affected devices. Given that Vertiv equipment powers and cools data centers worldwide, successful exploitation could give attackers control over physical infrastructure management systems. Facilities relying on these products need to verify their firmware versions immediately. @threatcluster 3️⃣ SERVICENOW VULNERABILITY THREATENS AUSTRALIA PLATFORM DATA A security flaw in ServiceNow's Australia platform deployment could have exposed sensitive customer data to unauthorized access. The company detected anomalous database queries and says the activity was likely from bug bounty researchers rather than malicious actors. A fix was deployed on June 5th after customer security teams pushed back with proof-of-concept evidence. It serves as a reminder that even enterprise SaaS platforms are not immune to data exposure risks, and customer vigilance plays a crucial role in driving vendor response. @securityblvd 4️⃣ PROXMOX RELEASES MAIL GATEWAY 9.1 WITH ENCRYPTION UPGRADES In open-source security news, Proxmox shipped Mail Gateway 9.1 with significant changes to its quarantine and backup encryption systems. As one of the most popular open-source virtualization and mail filtering platforms, Proxmox's updates directly affect thousands of organizations running self-hosted email infrastructure. The encryption improvements strengthen data-at-rest protection for quarantined messages and backup archives — a critical update for organizations handling sensitive communications through their own infrastructure. @TheCyberSecHub 5️⃣ FIFA WORLD CUP 2026 BECOMES PHISHING GOLDMINE Arctic Wolf's research team documented a growing wave of cybercriminal campaigns exploiting the 2026 FIFA World Cup. Attackers are combining AI-powered social engineering, QR code abuse (what they call "smishing 2.0"), and infostealer malware delivery — all themed around match tickets, team merchandise, and broadcast access. The report highlights how threat actors now blend commodity malware kits with AI-generated content to increase infection rates at scale. With the tournament underway, the volume of these campaigns is only expected to grow. @upgradeoptions 6️⃣ HUMANITY PROTOCOL'S $36M HACK: SEVEN KEYS, ONE LAPTOP A brutal post-mortem from the Humanity Protocol hack reveals how operational security failures can undermine even the best cryptographic designs. Seven critical keys — including 3 of 6 Ethereum Safe signers, 3 of 5 BSC signers, and the admin hot wallet — were all stored on a single developer laptop. When malware compromised that machine, the multisig effectively became a single-sig. The $36 million loss was not a protocol vulnerability but a textbook case of key management negligence. A multisig is only as secure as the weakest device holding a signer key. @Va77ss 7️⃣ MLTBACKDOOR MALWARE EVADES EDR BY MASQUERADING AS CLOUD API TRAFFIC A new malware family called MLTBackdoor is slipping past major Endpoint Detection and Response platforms by disguising its command-and-control traffic as legitimate cloud API calls. This technique renders traditional signature-based defenses largely ineffective, as the malware's network behavior looks indistinguishable from normal cloud service communication. Security researchers are emphasizing that behavioral analysis and anomaly detection are now essential layers — simple signature matching no longer catches threats that blend into enterprise cloud traffic patterns. @JNitterauer 8️⃣ THE REAL COST OF RANSOMWARE: IT'S NOT THE RANSOM A sobering look at three decades of ransomware attacks reveals a consistent pattern: the ransom payment is rarely the most expensive part. Norsk Hydro was forced to put 35,000 employees back to pen and paper after an attack. Maersk suffered approximately $300 million in operational disruption losses. Companies aren't brought to their knees by the ransom note — they're ground down by downtime, recovery costs, supply chain breakdowns, and lost revenue. The real metric isn't how much the attackers demand, but how long your business can survive offline. @bomberjacketnet 💭 The common thread across today's stories is that attackers are getting smarter about hiding in plain sight. Whether it's Linux kernel bugs that only matter after initial access, malware disguised as cloud API traffic, or supply chain vulnerabilities in critical infrastructure gear — the modern threat landscape rewards patience and punishes complacency. Defense in depth isn't optional anymore; it's the baseline. Which of these stories surprised you the most, and are you patching your systems regularly? 👇 #Cybersecurity #OpenSource #InfoSec #ThreatIntelligence #DataBreach

    Post summary

    The bulletin reports several newly disclosed vulnerabilities, notably a Linux kernel privilege‑escalation flaw (CVE‑2026‑23111) with publicly circulating exploit code, alongside critical infrastructure and SaaS platform exposures, underscoring the urgency of applying vendor patches.

    12041847
    2.7K followersView on X
  • IT SPARC Cast@ITSPARCCast
    General

    One Character Broke Linux Security: CVE-2026-23111 Explained https://t.co/g458ioRbUc

    Post summary

    The tweet merely announces an explanation of CVE‑2026‑23111 without providing technical details, PoC, exploit code, or patch information.

    21130124
    474 followersView on X
  • Miggo Security@MiggoSecurity
    Exploit

    A security patch created a Linux root exploit. One character (!) caused it. Every major Linux distro exposed for 2.5 years. That's CVE-2026-23111. Two research teams found it. We built the exploit, took it to full root, then built a detector that catches it whether or not you've patched. https://www.miggo.io/post/the-security-patch-that-created-a-vulnerability-miggo-security-releases-detector-for-cve-2026-23111-to-catch-an-attack-before-a-fix @ExodusIntel @FuzzingLabs #CVE202623111

    Post summary

    The post announces the discovery of CVE‑2026‑23111, a root‑escalation flaw on Linux, and the development of a full exploit plus a detector that identifies the exploit regardless of patch status.

    00032197
    142 followersView on X
  • Xakep.ru@XakepRU
    Disclosure

    Уязвимость в ядре Linux возникла всего из-за одного символа В Linux обнаружили уязвимость CVE-2026-23111 (7,8 балла по шкале CVSS), которая позволяла непривилегированному локальному пользователю повысить привилегии до уровня root. https://xakep.ru/2026/06/11/cve-2026-23111/

    Post summary

    The Linux kernel CVE-2026-23111 is a 7.8‑CVSS privilege‑elevation flaw allowing local users to become root.

    00031420
    46.1K followersView on X
  • Elusive@ElusivePrivacy
    PoC

    Linux Kernel LPE CVE-2026-23111 1/4 CVE-2026-23111 Linux kernel nf_tables. Root from unprivileged user. Container breakout included. Working exploit has been public for 4 months. If your kernel hasn’t been updated since February 5, 2026, you’re exposed right now. @VulnerabilityNw

    Post summary

    CVE-2026-23111 is a local privilege‑escalation flaw in Linux kernel nf_tables, with a public working exploit available for four months and poses risk to all systems not patched since February 5, 2026.

    10120192
    177 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Linux カーネルの新たな脆弱性 CVE-2026-23111 が FIX:root 権限昇格エクスプロイトが公開 https://iototsecnews.jp/2026/06/08/new-linux-kernel-vulnerability-lets-attackers-escalate-privileges-to-root/ 脆弱性 CVE-2026-23111 は、プログラム内の非常に小さなミスが原因で発生しています。具体的には、プログラムの条件判定で使われる論理否定演算子である「!」の配置ミスという、開発現場でも起こりやすいコードの書き間違いが発端となっています。この逆条件チェックのミスにより、処理の途中で特定の要素を再アクティブ化する手続きが誤ってスキップされてしまいました。その結果、本来であれば連動して動くはずの参照カウンタの計算に狂いが生じ、メモリの管理に矛盾が発生して重大なセキュリティ・リスクにつながっています。ご利用のチームは、ご注意ください。 #CVE202623111 #LinuxKernel #Vulnerability

    Post summary

    The article announces Linux kernel CVE-2026‑23111, detailing a small code error that corrupts reference counting and enables root privilege escalation, and reports that a public exploit has been released.

    02001170
    499 followersView on X
  • ProtAAPP - Protege las AAPP@ProtAAPP
    Patch

    Investigadores de Hispasec han descubierto una vulnerabilidad en nf_tables que permite a un usuario sin privilegios escalar a root en sistemas con user namespaces y NF_TABLES activados. El fallo, CVE-2026-23111, se corrige desde el 5 de febrero de 2026. https://unaaldia.hispasec.com/un-fallo-en-nftables-permite-escalar-a-root-en-linux-con-un-exploit-estable/?utm_source=rss&utm_medium=rss&utm_campaign=un-fallo-en-nftables-permite-escalar-a-root-en-linux-con-un-exploit-estable https://t.co/oGa4WeeTeU

    Post summary

    Hispasec disclosed a privilege‑escalation flaw in Linux’s nf_tables, now fixed with a kernel update released on February 5, 2026, and a stable exploit is referenced though no wild exploitation is reported.

    01020191
    8.3K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.4--

Explore more