Junglewise Threat Intelligence

CVE-2026-23111: Linux Kernel use-after-free in nf_tables catchall activation

CVE-2026-23111 · Severity: high · CVSS 7.8 · Published 2026-02-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to gain administrative privileges. The issue exists in the nftables component, which manages firewall rules and network traffic filtering. By exploiting a logic error during specific network configuration changes, an attacker can cause the system to crash or execute unauthorized code, potentially taking full control of the affected machine.

Technical details

A logic error exists in the nft_map_catchall_activate() function within the nf_tables component of the Linux kernel. The function contains an inverted genmask check that causes it to skip inactive elements and process active ones during an abort path, which is the opposite of the intended behavior. When a DELSET operation is aborted, this prevents the restoration of reference counts for catchall elements. Repeated abort cycles can decrement a chain's reference count to zero, allowing the chain to be freed while catchall elements still reference it. This results in a use-after-free condition that can be exploited for local privilege escalation, particularly on systems with CONFIG_USER_NS and CONFIG_NF_TABLES enabled. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 4.19.316 to 4.20, 5.4.262 to 5.5, 5.10.188 to 5.11, 5.15.121 to 5.15.200, 6.1.36 to 6.1.163, 6.3.10 to 6.4, 6.4.1 to 6.6.124, 6.7 to 6.12.70, 6.13 to 6.18.10

Timeline

  • 2026-02-13: advisory: CVE-2026-23111 published by kernel.org
  • 2026-02-11: patched: Commits applied to stable kernel trees by Greg Kroah-Hartman

References

Related threats