Blog.Exodusintel Linux Kernel CVE-2026-23111 Enables Local Privilege Escalation via nftables
Article Content
- •CVE-2026-23111 allows local privilege escalation to root via a use-after-free flaw.
- •The vulnerability affects major Linux distributions, including Debian and Ubuntu.
- •A proof of concept for exploiting the vulnerability was released on June 9, 2026.
A use-after-free vulnerability in the Linux kernel's nftables subsystem, tracked as CVE-2026-23111, allows local attackers to escalate privileges to root. Discovered in early 2025, the flaw was patched on February 5, 2026. It affects widely used distributions including Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. The vulnerability is exploited by leveraging a logic error in the code, which has been demonstrated in a proof of concept released on June 9, 2026. Security researchers from Exodus Intelligence conducted a detailed analysis and exploitation of this vulnerability. The flaw poses a significant risk to systems running affected Linux distributions, especially in environments where local access is possible.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-23111 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical SSRF and UAF Vulnerabilities Discovered in SonicWall and Linux Kernel Two critical vulnerabilities have been reported on September 7, 2026. CVE-2026-15409 is a critical Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 series devices, allowing remote attackers to execute unintended HTTP requests. This vulnerability has been actively exploited since its disclosure on…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…