Blog.Exodusintel
Linux Kernel CVE-2026-23111 Enables Local Privilege Escalation via nftables
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A use-after-free vulnerability in the Linux kernel's nftables subsystem, tracked as CVE-2026-23111, allows local attackers to escalate privileges to root. Discovered in early 2025, the flaw was patched on February 5, 2026. It affects widely used distributions including Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. The vulnerability is exploited by leveraging a logic error in the code, which has been demonstrated in a proof of concept released on June 9, 2026. Security researchers from Exodus Intelligence conducted a detailed analysis and exploitation of this vulnerability. The flaw poses a significant risk to systems running affected Linux distributions, especially in environments where local access is possible.
Key Points: • CVE-2026-23111 allows local privilege escalation to root via a use-after-free flaw. • The vulnerability affects major Linux distributions, including Debian and Ubuntu. • A proof of concept for exploiting the vulnerability was released on June 9, 2026.