PT-2026-7991 · Linux+3 · Linux Kernel+3

CVE-2026-23111

·

Published

2026-01-01

·

Updated

2026-09-03

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the nf tables component of the Linux kernel. The function nft map catchall activate() contains a logic bug where an inverted element activity check is performed during the abort path of a failed transaction. Specifically, the function incorrectly skips inactive elements and processes active ones, which is the opposite of the required behavior seen in nft mapelem activate().
When a DELSET operation is aborted, nft setelem data activate() is not called for the catchall element. For NFT GOTO verdict elements, this prevents nft data hold() from restoring the chain->use reference count. Repeated abort cycles permanently decrement chain->use until it reaches zero, allowing a DELCHAIN operation to free the chain while catchall verdict elements still reference it. A local low-privileged user can exploit this via user namespaces and nftables on distributions where CONFIG USER NS and CONFIG NF TABLES are enabled to cause a denial of service, achieve local privilege escalation to root, or escape containers.
Recommendations Update the Linux kernel to the version containing the fix applied on February 5, 2026. As a temporary mitigation, restrict the ability of unprivileged users to create network namespaces by setting kernel.unprivileged userns clone=0.

Exploit

Fix

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:18134
ALSA-2026:6570
AZL-77483
BDU:2026-08031
CVE-2026-23111
ECHO-F61A-DB70-FEB9
LSN-0119-1
OESA-2026-1760
OESA-2026-1832
OESA-2026-1833
OPENSUSE-SU-2026:20416-1
RHSA-2026:10108
RHSA-2026:10996
RHSA-2026:18134
RHSA-2026:6570
RHSA-2026:9112
SUSE-SU-2026:0962-1
SUSE-SU-2026:1041-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:1180-1
SUSE-SU-2026:1185-1
SUSE-SU-2026:1187-1
SUSE-SU-2026:1188-1
SUSE-SU-2026:1189-1
SUSE-SU-2026:1225-1
SUSE-SU-2026:1236-1
SUSE-SU-2026:1239-1
SUSE-SU-2026:1244-1
SUSE-SU-2026:1259-1
SUSE-SU-2026:1261-1
SUSE-SU-2026:1262-1
SUSE-SU-2026:1266-1
SUSE-SU-2026:1271-1
SUSE-SU-2026:1272-1
SUSE-SU-2026:1274-1
SUSE-SU-2026:1278-1
SUSE-SU-2026:1279-1
SUSE-SU-2026:1283-1
SUSE-SU-2026:1284-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20873-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21004-1
SUSE-SU-2026:21005-1
SUSE-SU-2026:21006-1
SUSE-SU-2026:21007-1
SUSE-SU-2026:21008-1
SUSE-SU-2026:21009-1
SUSE-SU-2026:21020-1
SUSE-SU-2026:21040-1
SUSE-SU-2026:21041-1
SUSE-SU-2026:21042-1
SUSE-SU-2026:21043-1
SUSE-SU-2026:21044-1
SUSE-SU-2026:21045-1
SUSE-SU-2026:21046-1
SUSE-SU-2026:21047-1
SUSE-SU-2026:21048-1
SUSE-SU-2026:21049-1
SUSE-SU-2026:21050-1
SUSE-SU-2026:21051-1
SUSE-SU-2026:21052-1
SUSE-SU-2026:21053-1
SUSE-SU-2026:21054-1
SUSE-SU-2026:21055-1
SUSE-SU-2026:21056-1
SUSE-SU-2026:21057-1
SUSE-SU-2026:21058-1
SUSE-SU-2026:21059-1
SUSE-SU-2026:21060-1
SUSE-SU-2026:21061-1
SUSE-SU-2026:21070-1
SUSE-SU-2026:21071-1
SUSE-SU-2026:21072-1
SUSE-SU-2026:21073-1
SUSE-SU-2026:21074-1
SUSE-SU-2026:21075-1
SUSE-SU-2026:21076-1
SUSE-SU-2026:21077-1
SUSE-SU-2026:21078-1
SUSE-SU-2026:21079-1
SUSE-SU-2026:21080-1
SUSE-SU-2026:21081-1
SUSE-SU-2026:21082-1
SUSE-SU-2026:21083-1
SUSE-SU-2026:21084-1
SUSE-SU-2026:21085-1
SUSE-SU-2026:21086-1
SUSE-SU-2026:21087-1
SUSE-SU-2026:21088-1
SUSE-SU-2026:21089-1
SUSE-SU-2026:21090-1
SUSE-SU-2026:21091-1
SUSE-SU-2026:21096-1
SUSE-SU-2026:21098-1
SUSE-SU-2026:21099-1
SUSE-SU-2026:21100-1
SUSE-SU-2026:21102-1
SUSE-SU-2026:21216-1
SUSE-SU-2026:21217-1
SUSE-SU-2026:21218-1
SUSE-SU-2026:21219-1
SUSE-SU-2026:21220-1
SUSE-SU-2026:21221-1
SUSE-SU-2026:21284-1
USN-8148-1
USN-8148-2
USN-8148-3
USN-8148-4
USN-8148-5
USN-8148-6
USN-8148-7
USN-8149-1
USN-8149-2
USN-8149-3
USN-8152-1
USN-8159-1
USN-8159-2
USN-8159-3
USN-8162-1
USN-8163-1
USN-8163-2
USN-8164-1
USN-8165-1
USN-8188-1
USN-8203-1
USN-8243-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu