Skip to main content
Mallory
Back to intelligence
privilege-escalation-techniqueendpoint-software-vulnerabilityproof-of-concept-releasewidely-deployed-product-advisory

Linux kernel use-after-free flaws enable local privilege escalation to root

Updated 1d agoFirst seen Jun 1, 20267 sources

Two Linux kernel use-after-free vulnerabilities were disclosed in packet-filtering components, exposing systems to local privilege escalation. CVE-2026-23111 affects the nftables subsystem and stems from an inverted conditional in nft_map_catchall_activate() that mishandles catchall elements during transaction aborts, leaving a dangling chain reference. A public technical write-up and working exploit showed the bug can achieve root privileges with high reliability on Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS by corrupting chain reference counts, bypassing KASLR, leaking heap addresses, hijacking control flow with a fake nft_expr_ops structure, and executing a ROP chain that calls commit_creds(&init_cred). The exploit also uses switch_task_namespaces() to break out of namespaces and containers.

A separate flaw, CVE-2026-23412, affects the Linux kernel’s BPF netfilter link implementation in nf_bpf_link.c, where synchronous deallocation of bpf_nf_link_lops allowed concurrent nfnetlink hook enumeration to access freed memory during BPF link destruction. Researchers reproduced KASAN slab-use-after-free crashes in nfnl_hook_dump_one on kernel 6.14.0 and said the bug could be exploited through heap spraying and function-pointer hijacking in the kmalloc-192 slab cache. The issue was introduced in 6.4-rc1 and fixed in 7.0-rc5 by commit 24f90fa3994b, which switches to RCU-deferred freeing, while the nftables bug was patched upstream by commit f41c5d1; administrators were urged to deploy patched kernels promptly.

Share:
Linux kernel use-after-free flaws enable local privilege escalation to root
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jun 9, 20262d ago

RHEL 10 confirmed vulnerable to CVE-2026-23111

The new report states that testing confirmed CVE-2026-23111 affects RHEL 10 in addition to previously reported Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS systems. The article also notes Ubuntu and Debian have issued patches while other vendors are tracking the flaw.

CVE-2026-23111: One Bad Character Gives Attackers Linux Root | The CyberSec Guru
Jun 8, 20262d ago

FuzzingLabs publishes CVE-2026-23111 exploit reproduction

The reference states that FuzzingLabs published a reproduction of the CVE-2026-23111 exploit in April 2026, making exploit details publicly available before the later June 8 technical walkthrough by Exodus Intelligence. This represents an earlier public technical disclosure related to the flaw.

One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

Public technical write-up and exploit disclosed for CVE-2026-23111

CVE-2026-23111 was publicly disclosed with a technical write-up and working exploit demonstrating root privilege escalation and namespace breakout. The disclosure reported impact on Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.

New Linux Kernel Vulnerability Lets Attackers Escalate Privileges to Root - Cyber Security News

CVE-2026-23111 discovered in Linux kernel nftables

Oliver Sieber of Exodus Intelligence discovered a local privilege escalation vulnerability in the Linux kernel nftables subsystem in early 2025. The bug is a use-after-free tied to mishandling of catchall elements during transaction aborts.

New Linux Kernel Vulnerability Lets Attackers Escalate Privileges to Root - Cyber Security News
May 18, 202624d ago

Aretiq AI publishes analysis of CVE-2026-23412

Aretiq AI published research describing CVE-2026-23412 as a Linux kernel local privilege escalation vulnerability affecting the BPF netfilter link implementation. The write-up said the issue was reproducible on kernel 6.14.0 and exploitable via heap spraying and function pointer hijacking.

CVE-2026-23412 - Linux Kernel Netfilter BPF Hook Use-After-Free LPE | Aretiq AI

Linux kernel 7.0-rc5 fixes CVE-2026-23412

A use-after-free flaw in the Linux kernel's BPF netfilter link implementation, tracked as CVE-2026-23412, was fixed in kernel 7.0-rc5 by commit 24f90fa3994b. The change deferred freeing with RCU to prevent concurrent hook enumeration from accessing freed memory.

CVE-2026-23412 - Linux Kernel Netfilter BPF Hook Use-After-Free LPE | Aretiq AI
Feb 5, 20264mo ago

Upstream patch released for CVE-2026-23111

The Linux kernel upstream patched CVE-2026-23111 on 2026-02-05. The fix is identified as commit f41c5d1, and administrators were advised to deploy patched kernels.

New Linux Kernel Vulnerability Lets Attackers Escalate Privileges to Root - Cyber Security News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.