{"id":"CVE-2026-23111","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()\n\nnft_map_catchall_activate() has an inverted element activity check\ncompared to its non-…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()\n\nnft_map_catchall_activate() has an inverted element activity check\ncompared to its non-…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-672"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 4.19.316, < 4.20","linux_kernel >= 5.4.262, < 5.5","linux_kernel >= 5.10.188, < 5.11","linux_kernel >= 5.15.121, < 5.15.200","linux_kernel >= 6.1.36, < 6.1.163","linux_kernel >= 6.3.10, < 6.4","linux_kernel >= 6.4.1, < 6.6.124","linux_kernel >= 6.7, < 6.12.70","linux_kernel >= 6.13, < 6.18.10","linux_kernel = 6.4","linux_kernel = 6.19"],"patched":["linux_kernel 6.18.10"],"published":"2026-02-13","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-23111","references":[{"url":"https://git.kernel.org/stable/c/1444ff890b4653add12f734ffeffc173d42862dd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42c574c1504aa089a0a142e4c13859327570473d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b68a45f9722f2babe9e7bad00aa74638addf081","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c760ba4e36c750379d13569f23f5a6e185333f5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9b6573421de51829f7ec1cce76d85f5f6fbbd7f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f41c5d151078c5348271ffaf8e7410d96f2d82f8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://access.redhat.com/errata/RHSA-2026:10108","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10996","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:18134","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6570","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9112","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23111","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2439687","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23111.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00489,"epssPercentile":0.41155,"ingestedAt":"2026-07-03T18:53:52.422Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-06-09T13:07:47.429787Z"},"exploits":{"github":10,"githubRepos":["https://github.com/HORKimhab/CVE-2026-23111","https://github.com/criann/check-cve-2026-23111","https://github.com/0xBlackash/CVE-2026-23111"],"checkedAt":"2026-09-23T07:13:55.013Z"},"exploitAvailable":true,"slug":"CVE-2026-23111","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()\n\nnft_map_catchall_activate() has an inverted element activity check\ncompared to its non-catchall counterpart nft_mapelem_activate() and\ncompared to what is logically required.\n\nnft_map_catchall_activate() is called from the abort path to re-activate\ncatchall map elements that were deactivated during a failed transaction.\nIt should skip elements that are already active (they don't need\nre-activation) and process elements that are inactive (they need to be\nrestored). Instead, the current code does the opposite: it skips inactive\nelements and processes active ones.\n\nCompare the non-catchall activate callback, which is correct:\n\n  nft_mapelem_activate():\n    if (nft_set_elem_active(ext, iter->genmask))\n        return 0;   /* skip active, process inactive */\n\nWith the buggy catchall version:\n\n  nft_map_catchall_activate():\n    if (!nft_set_elem_active(ext, genmask))\n        continue;   /* skip inactive, process active */\n\nThe consequence is that when a DELSET operation is aborted,\nnft_setelem_data_activate() is never called for the catchall element.\nFor NFT_GOTO verdict elements, this means nft_data_hold() is never\ncalled to restore the chain->use reference count. Each abort cycle\npermanently decrements chain->use. Once chain->use reaches zero,\nDELCHAIN succeeds and frees the chain while catchall verdict elements\nstill reference it, resulting in a use-after-free.\n\nThis is exploitable for local privilege escalation from an unprivileged\nuser via user namespaces + nftables on distributions that enable\nCONFIG_USER_NS and CONFIG_NF_TABLES.\n\nFix by removing the negation so the check matches nft_mapelem_activate():\nskip active elements, process inactive ones.\n\n## Affected\n\n- `linux_kernel >= 4.19.316, < 4.20`\n- `linux_kernel >= 5.4.262, < 5.5`\n- `linux_kernel >= 5.10.188, < 5.11`\n- `linux_kernel >= 5.15.121, < 5.15.200`\n- `linux_kernel >= 6.1.36, < 6.1.163`\n- `linux_kernel >= 6.3.10, < 6.4`\n- `linux_kernel >= 6.4.1, < 6.6.124`\n- `linux_kernel >= 6.7, < 6.12.70`\n- `linux_kernel >= 6.13, < 6.18.10`\n- `linux_kernel = 6.4`\n- `linux_kernel = 6.19`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.18.10`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5016,"id":"CVE-2026-23111","ts":1788887228504,"field":"exploit_available","old":"false","new":"true"},{"seq":3899,"id":"CVE-2026-23111","ts":1788886359795,"field":"exploit_available","old":"true","new":"false"},{"seq":2721,"id":"CVE-2026-23111","ts":1788883025254,"field":"exploit_available","old":"false","new":"true"},{"seq":1750,"id":"CVE-2026-23111","ts":1788882429550,"field":"exploit_available","old":"true","new":"false"},{"seq":856,"id":"CVE-2026-23111","ts":1788881862589,"field":"exploit_available","old":"false","new":"true"}]}