PT-2026-7991 · Linux+3 · Linux Kernel+3

CVE-2026-23111

·

Published

2026-01-01

·

Updated

2026-07-18

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the nf tables component of the Linux kernel. The nft map catchall activate() function contains a logic bug where an inverted element activity check is performed during the abort path of a failed transaction. Specifically, the function incorrectly skips inactive elements and processes active ones, which is the opposite of the required behavior seen in nft mapelem activate().
When a DELSET operation is aborted, nft setelem data activate() is not called for the catchall element. For NFT GOTO verdict elements, this prevents nft data hold() from restoring the chain->use reference count. Repeated abort cycles permanently decrement chain->use until it reaches zero, allowing a DELCHAIN operation to free the chain while catchall verdict elements still reference it. A local low-privileged user can exploit this via user namespaces and nftables on distributions where CONFIG USER NS and CONFIG NF TABLES are enabled to achieve local privilege escalation to root and escape containers.
Recommendations Update the Linux kernel to the version containing the patch released on February 5, 2026. As a temporary mitigation, restrict the ability of unprivileged users to create network namespaces by setting kernel.unprivileged userns clone=0.

Exploit

Fix

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:18134
ALSA-2026:6570
BDU:2026-08031
CVE-2026-23111
ECHO-F61A-DB70-FEB9
LSN-0119-1
OESA-2026-1760
OPENSUSE-SU-2026:20416-1
RHSA-2026:10108
RHSA-2026:10996
RHSA-2026:18134
RHSA-2026:6570
RHSA-2026:9112
SUSE-SU-2026:0962-1
SUSE-SU-2026:1041-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:1180-1
SUSE-SU-2026:1185-1
SUSE-SU-2026:1187-1
SUSE-SU-2026:1188-1
SUSE-SU-2026:1189-1
SUSE-SU-2026:1225-1
SUSE-SU-2026:1236-1
SUSE-SU-2026:1239-1
SUSE-SU-2026:1244-1
SUSE-SU-2026:1259-1
SUSE-SU-2026:1261-1
SUSE-SU-2026:1262-1
SUSE-SU-2026:1266-1
SUSE-SU-2026:1271-1
SUSE-SU-2026:1272-1
SUSE-SU-2026:1274-1
SUSE-SU-2026:1278-1
SUSE-SU-2026:1279-1
SUSE-SU-2026:1283-1
SUSE-SU-2026:1284-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20873-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21004-1
SUSE-SU-2026:21005-1
SUSE-SU-2026:21006-1
SUSE-SU-2026:21007-1
SUSE-SU-2026:21008-1
SUSE-SU-2026:21009-1
SUSE-SU-2026:21020-1
SUSE-SU-2026:21040-1
SUSE-SU-2026:21041-1
SUSE-SU-2026:21042-1
SUSE-SU-2026:21043-1
SUSE-SU-2026:21044-1
SUSE-SU-2026:21045-1
SUSE-SU-2026:21046-1
SUSE-SU-2026:21047-1
SUSE-SU-2026:21048-1
SUSE-SU-2026:21049-1
SUSE-SU-2026:21050-1
SUSE-SU-2026:21051-1
SUSE-SU-2026:21052-1
SUSE-SU-2026:21053-1
SUSE-SU-2026:21054-1
SUSE-SU-2026:21055-1
SUSE-SU-2026:21056-1
SUSE-SU-2026:21057-1
SUSE-SU-2026:21058-1
SUSE-SU-2026:21059-1
SUSE-SU-2026:21060-1
SUSE-SU-2026:21061-1
SUSE-SU-2026:21070-1
SUSE-SU-2026:21071-1
SUSE-SU-2026:21072-1
SUSE-SU-2026:21073-1
SUSE-SU-2026:21074-1
SUSE-SU-2026:21075-1
SUSE-SU-2026:21076-1
SUSE-SU-2026:21077-1
SUSE-SU-2026:21078-1
SUSE-SU-2026:21079-1
SUSE-SU-2026:21080-1
SUSE-SU-2026:21081-1
SUSE-SU-2026:21082-1
SUSE-SU-2026:21083-1
SUSE-SU-2026:21084-1
SUSE-SU-2026:21085-1
SUSE-SU-2026:21086-1
SUSE-SU-2026:21087-1
SUSE-SU-2026:21088-1
SUSE-SU-2026:21089-1
SUSE-SU-2026:21090-1
SUSE-SU-2026:21091-1
SUSE-SU-2026:21096-1
SUSE-SU-2026:21098-1
SUSE-SU-2026:21099-1
SUSE-SU-2026:21100-1
SUSE-SU-2026:21102-1
SUSE-SU-2026:21216-1
SUSE-SU-2026:21217-1
SUSE-SU-2026:21218-1
SUSE-SU-2026:21219-1
SUSE-SU-2026:21220-1
SUSE-SU-2026:21221-1
SUSE-SU-2026:21284-1
USN-8148-1
USN-8148-2
USN-8148-3
USN-8148-4
USN-8148-5
USN-8148-6
USN-8148-7
USN-8149-1
USN-8149-2
USN-8149-3
USN-8152-1
USN-8159-1
USN-8159-2
USN-8159-3
USN-8162-1
USN-8163-1
USN-8163-2
USN-8164-1
USN-8165-1
USN-8188-1
USN-8203-1
USN-8243-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu