Exploitation observed; activity peaked at 28 mentions and remains active
Immediate actions
Patch linux linux_kernel systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
nft_map_catchall_activate() has an inverted element activity check
compared to its non-catchall counterpart nft_mapelem_activate() and
compared to what is logically required.
nft_map_catchall_activate() is called from the abort path to re-activate
catchall map elements that were deactivated during a failed transaction.
It should skip elements that are already active (they don't need
re-activation) and process elements that are inactive (they need to be
restored). Instead, the current code does the opposite: it skips inactive
elements and processes active ones.
Compare the non-catchall activate callback, which is correct:
nft_mapelem_activate():
if (nft_set_elem_active(ext, iter->genmask))
return 0; /* skip active, process inactive */
With the buggy catchall version:
nft_map_catchall_activate():
if (!nft_set_elem_active(ext, genmask))
continue; /* skip inactive, process active */
The consequence is that when a DELSET operation is aborted,
nft_setelem_data_activate() is never called for the catchall element.
For NFT_GOTO verdict elements, this means nft_data_hold() is never
called to restore the chain->use reference count. Each abort cycle
permanently decrements chain->use. Once chain->use reaches zero,
DELCHAIN succeeds and frees the chain while catchall verdict elements
still reference it, resulting in a use-after-free.
This is exploitable for local privilege escalation from an unprivileged
user via user namespaces + nftables on distributions that enable
CONFIG_USER_NS and CONFIG_NF_TABLES.
Fix by removing the negation so the check matches nft_mapelem_activate():
skip active elements, process inactive ones.
Active Exploitation2Disclosure6Exploit5General6Patch5PoC4
2026-06-10
13
Active Exploitation1Disclosure6Exploit2General1Patch3
2026-06-11
8
Disclosure3Exploit4Patch1
2026-06-12
5
Active Exploitation1Disclosure2General1Patch1
2026-06-13
1
Exploit1
2026-06-15
1
PoC1
2026-06-17
1
Exploit1
2026-06-18
3
Disclosure1Exploit1General1
2026-06-19
1
Disclosure1
2026-06-25
2
PoC2
2026-06-26
1
PoC1
2026-06-27
2
Exploit1General1
2026-06-29
1
General1
2026-07-05
1
Disclosure1
2026-07-07
1
General1
2026-07-10
1
General1
2026-07-17
1
Disclosure1
2026-08-24
1
Disclosure1
2026-08-27
1
PoC1
2026-08-28
2
Disclosure2
>Full discourse20 posts
The Hacker News@TheHackersNews·
Exploit
🚨 A single stray "!" in the #Linux kernel's firewall code (nftables).
That one character let any normal logged-in user become root, and step out of the container.
The fix? One line.
And the exploit (CVE-2026-23111) to abuse it just went public.
Read: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html
Post summary
A single stray character in the Linux nftables firewall code creates a privilege escalation that’s now exposed via a publicly released exploit, while a one‑line patch is available to mitigate the flaw.
[CVE-2026-23111] A missing “!” in Linux kernel code leads to full root compromise 👾💥
🔗 https://fuzzinglabs.com/repro-cve-2026-23111/
🔗 https://t.me/luckyhacker42 https://t.co/spmiUEp7QV
Post summary
The post announces CVE‑2026‑23111, explains that a missing exclamation mark in Linux kernel code leads to root compromise, and provides a link to a reproducible proof‑of‑concept.
Nueva vulnerabilidad de Linux permite escalar privilegios a root
Se ha revelado una vulnerabilidad de tipo use-after-free en el subsistema nftables del kernel de Linux, identificada como CVE-2026-23111
https://blog.elhacker.net/2026/06/nueva-vulnerabilidad-de-linux-permite.html
Post summary
A new use‑after‑free vulnerability (CVE-2026-23111) in the Linux nftables kernel subsystem has been disclosed, but no PoC, exploit, active exploitation, patch, or debunking information is provided.
This is the kind of Linux bug attackers love.
> Not remote
> Not flashy
> Easy to miss
But once they already have a small foothold, it can turn that access into full control of the host.
CVE-2026-23111 now has public exploit details.
Patch + reboot: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html https://t.co/bKrv66Opb5
Post summary
The post announces that CVE-2026-23111 has publicly available exploit details and recommends a patch with reboot, but it does not provide a specific exploit tool, evidence of active attacks, or technical vulnerability specifics.
Off By !: Exploiting a Use-after-Free in the Linux Kernel
Oliver Sieber published write-up on CVE-2026-23111 in nftables, found in early 2025, patched upstream by other researchers in Feb 2026. Article describes exploiting this UAF on Debian and Ubuntu.
https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/
Post summary
The post announces a write‑up of a use‑after‑free vulnerability in nftables (CVE‑2026‑23111) with a PoC, notes the discovery was patched, but no active exploitation or detailed exploit tool is disclosed.
We reproduced and analyzed CVE-2026-23111, a Linux kernel vulnerability in nftables that led to a use-after-free which we leveraged to achieve local privilege escalation.
Full write-up:
https://fuzzinglabs.com/repro-cve-2026-23111/ https://t.co/8OEKK3FG3g
Post summary
The post documents the reproduction and analysis of CVE‑2026‑23111, a Linux kernel use‑after‑free in nftables that can lead to local privilege escalation, and links to a write‑up containing technical details.
[CVE-2026-23111] A missing “!” in Linux kernel code leads to full root compromise 👾💥
🔗 https://fuzzinglabs.com/repro-cve-2026-23111/
🔗 https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html
🔗 https://cybersecuritynews.com/linux-kernel-nftables-vulnerability/
👉 http://t.me/luckyhacker42 https://t.co/8JfgBt6U95
Post summary
CVE‑2026‑23111 is a newly disclosed Linux kernel flaw where a missing exclamation mark can lead to full root compromise; proof of concept links are provided, but no active exploitation, patch, or debunking information is present.
Linux Kernel nf_tables Use-After-Free Vulnerability
CVE: CVE-2026-23111
PT ID: PT-2026-7991
Vendor: Linux
Product: Linux
CVSS: 7.8
Credits: n/a
Description:
A use-after-free issue exists in the "nf tables" component of the Linux kernel. The function "nft map catchall activate()" contains an inverted element activity check compared to the logically required behavior and its counterpart "nft mapelem activate()". Specifically, the function incorrectly skips inactive elements and processes active ones during the abort path used to re-activate catchall map elements after a failed transaction.
When a "DELSET" operation is aborted, "nft setelem data activate()" is not called for the catchall element. For "NFT GOTO" verdict elements, this prevents "nft data hold()" from restoring the "chain->use" reference count. Repeated abort cycles permanently decrement "chain->use" until it reaches zero, allowing a "DELCHAIN" operation to free the chain while catchall verdict elements still reference it. This can be exploited by an unprivileged local user to achieve local privilege escalation to root and escape containers on distributions where "CONFIG USER NS" and "CONFIG NF TABLES" are enabled.
References:
• https://dbugs.ptsecurity.com/vulnerability/CVE-2026-23111
• https://git.kernel.org/stable/c/8c760ba4e36c750379d13569f23f5a6e185333f5
PoC/Exploit: https://github.com/Baba01hacker666/CVE-2026-23111
#dbugs_vuln
Post summary
A locally exploitable use‑after‑free in Linux nf_tables is disclosed with technical details and a linked PoC/Exploit repository, but no evidence of live exploitation or patch availability.
CVE‑2026‑23111 is a local privilege escalation in Linux nftables; a proof‑of‑concept exploit with high success rates has been released, and vendors have issued kernel patches with temporary mitigations advised.
Critical Linux kernel use-after-free in nftables enables unprivileged local privilege escalation to root. CVE-2026-23111 affects major distributions including Debian and Ubuntu systems.
Technical details:
• Flaw in nft_map_catchall_activate() function incorrectly skips deactivated catchall elements during abort process
• Vulnerability triggered via crafted netlink batches: delete pipapo set → force abort → toggle generation → delete set → delete chain
• Results in chain reference counter reaching zero while valid references remain, creating exploitable use-after-free
• Affects nftables subsystem generation mask handling and catchall element lifecycle management
Attack methodology:
• Requires unprivileged user namespace creation (bypassable on Ubuntu 24.04 via aa-exec)
• Multi-stage exploit: trigger vulnerability → leak kernel base (defeat KASLR) → leak heap addresses → ROP chain execution
• Achieves privilege escalation via commit_creds(&init_cred) and namespace escape through switch_task_namespaces()
• Stability >99% on idle systems, drops to 80% under load
Impact spans Debian Bookworm/Trixie and Ubuntu 22.04/24.04 LTS. Patch applied February 2026. Hunt for suspicious nftables operations with pipapo sets and generation cursor manipulation in audit logs.
#DFIR_Radar
Post summary
The post discloses a critical Linux kernel use‑after‑free in nftables, provides detailed exploitation steps, notes a patch timeline, and advises defenders to monitor suspicious nftables activity.
CVE-2026-23111: Linux nf_tables Flaw Enables Root Exploits https://securityaffairs.com/193352/hacking/cve-2026-23111-linux-nf_tables-flaw-enables-root-exploits.html
Post summary
The article announces a Linux nf_tables flaw that permits root privilege escalation, but provides no PoC, exploit code, patch, or evidence of active exploitation.
Detecting the nftables Catchall Use-After-Free (CVE-2026–23111) by thinking outside the box - Authored by Rafael David Tinoco https://medium.com/@miggo-engineering/detecting-the-nftables-catchall-use-after-free-cve-2026-23111-by-thinking-outside-the-box-2227654d5acf
Post summary
The Medium article discusses detecting the nftables Catchall Use-After-Free (CVE-2026‑23111) but provides no PoC, exploit, patch, or active exploitation details.
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — June 11, 2026
1️⃣ LINUX KERNEL PRIVILEGE ESCALATION BUG GETS PUBLIC EXPLOIT — CVE-2026-23111
A Linux kernel vulnerability rated as a favorite among attackers has gone public. CVE-2026-23111 is neither remote nor flashy, which makes it easy to overlook — but once an adversary has a small foothold on a system, this flaw can be leveraged to escalate to full host control. Public exploit code is now circulating, meaning any unpatched machine is sitting duck territory. The fix is straightforward: patch the kernel and reboot, but the window between disclosure and widespread patching is where the real damage happens.
@TheHackersNews
2️⃣ VERTIV DATA CENTER GEAR HIT WITH TWO CRITICAL CVEs
Critical infrastructure is in the crosshairs. Claroty's Team82 lab identified two vulnerabilities — CVE-2025-41426 and CVE-2025-46412 — in Vertiv's Liebert RDU101 and Liebert UNITY products. Both flaws allow arbitrary code execution and authentication bypass on affected devices. Given that Vertiv equipment powers and cools data centers worldwide, successful exploitation could give attackers control over physical infrastructure management systems. Facilities relying on these products need to verify their firmware versions immediately.
@threatcluster
3️⃣ SERVICENOW VULNERABILITY THREATENS AUSTRALIA PLATFORM DATA
A security flaw in ServiceNow's Australia platform deployment could have exposed sensitive customer data to unauthorized access. The company detected anomalous database queries and says the activity was likely from bug bounty researchers rather than malicious actors. A fix was deployed on June 5th after customer security teams pushed back with proof-of-concept evidence. It serves as a reminder that even enterprise SaaS platforms are not immune to data exposure risks, and customer vigilance plays a crucial role in driving vendor response.
@securityblvd
4️⃣ PROXMOX RELEASES MAIL GATEWAY 9.1 WITH ENCRYPTION UPGRADES
In open-source security news, Proxmox shipped Mail Gateway 9.1 with significant changes to its quarantine and backup encryption systems. As one of the most popular open-source virtualization and mail filtering platforms, Proxmox's updates directly affect thousands of organizations running self-hosted email infrastructure. The encryption improvements strengthen data-at-rest protection for quarantined messages and backup archives — a critical update for organizations handling sensitive communications through their own infrastructure.
@TheCyberSecHub
5️⃣ FIFA WORLD CUP 2026 BECOMES PHISHING GOLDMINE
Arctic Wolf's research team documented a growing wave of cybercriminal campaigns exploiting the 2026 FIFA World Cup. Attackers are combining AI-powered social engineering, QR code abuse (what they call "smishing 2.0"), and infostealer malware delivery — all themed around match tickets, team merchandise, and broadcast access. The report highlights how threat actors now blend commodity malware kits with AI-generated content to increase infection rates at scale. With the tournament underway, the volume of these campaigns is only expected to grow.
@upgradeoptions
6️⃣ HUMANITY PROTOCOL'S $36M HACK: SEVEN KEYS, ONE LAPTOP
A brutal post-mortem from the Humanity Protocol hack reveals how operational security failures can undermine even the best cryptographic designs. Seven critical keys — including 3 of 6 Ethereum Safe signers, 3 of 5 BSC signers, and the admin hot wallet — were all stored on a single developer laptop. When malware compromised that machine, the multisig effectively became a single-sig. The $36 million loss was not a protocol vulnerability but a textbook case of key management negligence. A multisig is only as secure as the weakest device holding a signer key.
@Va77ss
7️⃣ MLTBACKDOOR MALWARE EVADES EDR BY MASQUERADING AS CLOUD API TRAFFIC
A new malware family called MLTBackdoor is slipping past major Endpoint Detection and Response platforms by disguising its command-and-control traffic as legitimate cloud API calls. This technique renders traditional signature-based defenses largely ineffective, as the malware's network behavior looks indistinguishable from normal cloud service communication. Security researchers are emphasizing that behavioral analysis and anomaly detection are now essential layers — simple signature matching no longer catches threats that blend into enterprise cloud traffic patterns.
@JNitterauer
8️⃣ THE REAL COST OF RANSOMWARE: IT'S NOT THE RANSOM
A sobering look at three decades of ransomware attacks reveals a consistent pattern: the ransom payment is rarely the most expensive part. Norsk Hydro was forced to put 35,000 employees back to pen and paper after an attack. Maersk suffered approximately $300 million in operational disruption losses. Companies aren't brought to their knees by the ransom note — they're ground down by downtime, recovery costs, supply chain breakdowns, and lost revenue. The real metric isn't how much the attackers demand, but how long your business can survive offline.
@bomberjacketnet
💭 The common thread across today's stories is that attackers are getting smarter about hiding in plain sight. Whether it's Linux kernel bugs that only matter after initial access, malware disguised as cloud API traffic, or supply chain vulnerabilities in critical infrastructure gear — the modern threat landscape rewards patience and punishes complacency. Defense in depth isn't optional anymore; it's the baseline.
Which of these stories surprised you the most, and are you patching your systems regularly? 👇
#Cybersecurity#OpenSource#InfoSec#ThreatIntelligence#DataBreach
Post summary
The bulletin reports several newly disclosed vulnerabilities, notably a Linux kernel privilege‑escalation flaw (CVE‑2026‑23111) with publicly circulating exploit code, alongside critical infrastructure and SaaS platform exposures, underscoring the urgency of applying vendor patches.
A security patch created a Linux root exploit.
One character (!) caused it. Every major Linux distro exposed for 2.5 years. That's CVE-2026-23111.
Two research teams found it. We built the exploit, took it to full root, then built a detector that catches it whether or not you've patched.
https://www.miggo.io/post/the-security-patch-that-created-a-vulnerability-miggo-security-releases-detector-for-cve-2026-23111-to-catch-an-attack-before-a-fix
@ExodusIntel@FuzzingLabs#CVE202623111
Post summary
The post announces the discovery of CVE‑2026‑23111, a root‑escalation flaw on Linux, and the development of a full exploit plus a detector that identifies the exploit regardless of patch status.
Уязвимость в ядре Linux возникла всего из-за одного символа
В Linux обнаружили уязвимость CVE-2026-23111 (7,8 балла по шкале CVSS), которая позволяла непривилегированному локальному пользователю повысить привилегии до уровня root.
https://xakep.ru/2026/06/11/cve-2026-23111/
Post summary
The Linux kernel CVE-2026-23111 is a 7.8‑CVSS privilege‑elevation flaw allowing local users to become root.
Linux Kernel LPE CVE-2026-23111
1/4
CVE-2026-23111 Linux kernel nf_tables. Root from unprivileged user. Container breakout included. Working exploit has been public for 4 months.
If your kernel hasn’t been updated since February 5, 2026, you’re exposed right now.
@VulnerabilityNw
Post summary
CVE-2026-23111 is a local privilege‑escalation flaw in Linux kernel nf_tables, with a public working exploit available for four months and poses risk to all systems not patched since February 5, 2026.
The article announces Linux kernel CVE-2026‑23111, detailing a small code error that corrupts reference counting and enables root privilege escalation, and reports that a public exploit has been released.
Investigadores de Hispasec han descubierto una vulnerabilidad en nf_tables que permite a un usuario sin privilegios escalar a root en sistemas con user namespaces y NF_TABLES activados. El fallo, CVE-2026-23111, se corrige desde el 5 de febrero de 2026.
https://unaaldia.hispasec.com/un-fallo-en-nftables-permite-escalar-a-root-en-linux-con-un-exploit-estable/?utm_source=rss&utm_medium=rss&utm_campaign=un-fallo-en-nftables-permite-escalar-a-root-en-linux-con-un-exploit-estable https://t.co/oGa4WeeTeU
Post summary
Hispasec disclosed a privilege‑escalation flaw in Linux’s nf_tables, now fixed with a kernel update released on February 5, 2026, and a stable exploit is referenced though no wild exploitation is reported.