Linux Kernel CVE-2026-23111 Enables Local Privilege Escalation via nftables

Linux Kernel CVE-2026-23111 Enables Local Privilege Escalation via nftables

First seen 8 Jun 2026, 17:18 UTC Blog.ExodusintelCybersecuritynewsSecurityaffairs.CoGbhackers 81% similarity 74.0

Article Content

Browse articles
ThreatCluster

A use-after-free vulnerability in the Linux kernel's nftables subsystem, tracked as CVE-2026-23111, allows local attackers to escalate privileges to root. Discovered in early 2025, the flaw was patched on February 5, 2026. It affects widely used distributions including Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. The vulnerability is exploited by leveraging a logic error in the code, which has been demonstrated in a proof of concept released on June 9, 2026. Security researchers from Exodus Intelligence conducted a detailed analysis and exploitation of this vulnerability. The flaw poses a significant risk to systems running affected Linux distributions, especially in environments where local access is possible.

Key Points: • CVE-2026-23111 allows local privilege escalation to root via a use-after-free flaw. • The vulnerability affects major Linux distributions, including Debian and Ubuntu. • A proof of concept for exploiting the vulnerability was released on June 9, 2026.

ThreatCluster AI

Timeline

2025-01-01
Vulnerability discovered
A use-after-free vulnerability in the nftables subsystem was identified by Exodus Intelligence.
Blog.Exodusintel
2026-02-05
Patch released
The vulnerability CVE-2026-23111 was patched upstream in the Linux kernel.
Cybersecuritynews
2026-02-13
CVE-2026-23111 published
CVE-2026-23111 was officially published, detailing the use-after-free vulnerability.
Gbhackers
2026-06-09
Proof of Concept released
A proof of concept demonstrating the exploitation of CVE-2026-23111 was made public.
Gbhackers

Community

Browse all →

Tracked Entities in This Story