PT-2026-7991 · Linux+3 · Linux Kernel+3

Published

2026-01-01

·

Updated

2026-06-11

·

CVE-2026-23111

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the nf tables packet-filtering subsystem of the Linux kernel. The flaw is located in the nft map catchall activate() function, which contains an inverted element activity check. When a transaction deleting a catchall element inside an NFT SET MAP verdict map is aborted, the function incorrectly skips inactive elements and processes active ones. Consequently, nft setelem data activate() is never called for the catchall element, and for NFT GOTO verdict elements, nft data hold() is not called to restore the chain->use reference count.
Each abort cycle permanently decrements chain->use. Once this count reaches zero, a DELCHAIN operation can succeed and free the chain while catchall verdict elements still reference it. This can be exploited by an unprivileged local user to achieve local privilege escalation to root and container escape on distributions that enable CONFIG USER NS and CONFIG NF TABLES. The exploitation process involves crafted netlink batches to trigger the use-after-free, leak the kernel base to defeat KASLR (Kernel Address Space Layout Randomization), and execute a ROP (Return-Oriented Programming) chain to call commit creds(&init cred) and switch task namespaces().
Recommendations Update the Linux kernel to the version containing the fix applied on February 5, 2026. As a temporary mitigation, restrict unprivileged users from creating network namespaces by setting kernel.unprivileged userns clone=0.

Exploit

Fix

LPE

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2026:18134
ALSA-2026:6570
BDU:2026-08031
CVE-2026-23111
ECHO-F61A-DB70-FEB9
LSN-0119-1
OESA-2026-1760
OPENSUSE-SU-2026:20416-1
RHSA-2026:10108
RHSA-2026:10996
RHSA-2026:6570
RHSA-2026:9112
SUSE-SU-2026:0962-1
SUSE-SU-2026:1041-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:1180-1
SUSE-SU-2026:1185-1
SUSE-SU-2026:1187-1
SUSE-SU-2026:1188-1
SUSE-SU-2026:1189-1
SUSE-SU-2026:1225-1
SUSE-SU-2026:1236-1
SUSE-SU-2026:1239-1
SUSE-SU-2026:1244-1
SUSE-SU-2026:1259-1
SUSE-SU-2026:1261-1
SUSE-SU-2026:1262-1
SUSE-SU-2026:1266-1
SUSE-SU-2026:1271-1
SUSE-SU-2026:1272-1
SUSE-SU-2026:1274-1
SUSE-SU-2026:1278-1
SUSE-SU-2026:1279-1
SUSE-SU-2026:1283-1
SUSE-SU-2026:1284-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21004-1
SUSE-SU-2026:21005-1
SUSE-SU-2026:21006-1
SUSE-SU-2026:21007-1
SUSE-SU-2026:21008-1
SUSE-SU-2026:21009-1
SUSE-SU-2026:21020-1
SUSE-SU-2026:21040-1
SUSE-SU-2026:21041-1
SUSE-SU-2026:21042-1
SUSE-SU-2026:21043-1
SUSE-SU-2026:21044-1
SUSE-SU-2026:21045-1
SUSE-SU-2026:21046-1
SUSE-SU-2026:21047-1
SUSE-SU-2026:21048-1
SUSE-SU-2026:21049-1
SUSE-SU-2026:21050-1
SUSE-SU-2026:21051-1
SUSE-SU-2026:21052-1
SUSE-SU-2026:21053-1
SUSE-SU-2026:21054-1
SUSE-SU-2026:21055-1
SUSE-SU-2026:21056-1
SUSE-SU-2026:21057-1
SUSE-SU-2026:21058-1
SUSE-SU-2026:21059-1
SUSE-SU-2026:21060-1
SUSE-SU-2026:21061-1
SUSE-SU-2026:21070-1
SUSE-SU-2026:21071-1
SUSE-SU-2026:21072-1
SUSE-SU-2026:21073-1
SUSE-SU-2026:21074-1
SUSE-SU-2026:21075-1
SUSE-SU-2026:21076-1
SUSE-SU-2026:21077-1
SUSE-SU-2026:21078-1
SUSE-SU-2026:21079-1
SUSE-SU-2026:21080-1
SUSE-SU-2026:21081-1
SUSE-SU-2026:21082-1
SUSE-SU-2026:21083-1
SUSE-SU-2026:21084-1
SUSE-SU-2026:21085-1
SUSE-SU-2026:21086-1
SUSE-SU-2026:21087-1
SUSE-SU-2026:21088-1
SUSE-SU-2026:21089-1
SUSE-SU-2026:21090-1
SUSE-SU-2026:21091-1
SUSE-SU-2026:21096-1
SUSE-SU-2026:21098-1
SUSE-SU-2026:21099-1
SUSE-SU-2026:21100-1
SUSE-SU-2026:21102-1
SUSE-SU-2026:21216-1
SUSE-SU-2026:21217-1
SUSE-SU-2026:21218-1
SUSE-SU-2026:21219-1
SUSE-SU-2026:21220-1
SUSE-SU-2026:21221-1
SUSE-SU-2026:21284-1
USN-8148-1
USN-8148-2
USN-8148-3
USN-8148-4
USN-8148-5
USN-8148-6
USN-8148-7
USN-8149-1
USN-8149-2
USN-8149-3
USN-8152-1
USN-8159-1
USN-8159-2
USN-8159-3
USN-8162-1
USN-8163-1
USN-8163-2
USN-8164-1
USN-8165-1
USN-8188-1
USN-8203-1
USN-8243-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu