---
id: CVE-2026-23111
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  netfilter: nf_tables: fix inverted genmask check in
  nft_map_catchall_activate()


  nft_map_catchall_activate() has an inverted element activity check

  compared to its non-…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  netfilter: nf_tables: fix inverted genmask check in
  nft_map_catchall_activate()


  nft_map_catchall_activate() has an inverted element activity check

  compared to its non-…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
  - CWE-672
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.19.316, < 4.20'
  - 'linux_kernel >= 5.4.262, < 5.5'
  - 'linux_kernel >= 5.10.188, < 5.11'
  - 'linux_kernel >= 5.15.121, < 5.15.200'
  - 'linux_kernel >= 6.1.36, < 6.1.163'
  - 'linux_kernel >= 6.3.10, < 6.4'
  - 'linux_kernel >= 6.4.1, < 6.6.124'
  - 'linux_kernel >= 6.7, < 6.12.70'
  - 'linux_kernel >= 6.13, < 6.18.10'
  - linux_kernel = 6.4
  - linux_kernel = 6.19
patched:
  - linux_kernel 6.18.10
published: '2026-02-13'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23111'
references:
  - url: 'https://git.kernel.org/stable/c/1444ff890b4653add12f734ffeffc173d42862dd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/42c574c1504aa089a0a142e4c13859327570473d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8b68a45f9722f2babe9e7bad00aa74638addf081'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8c760ba4e36c750379d13569f23f5a6e185333f5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b9b6573421de51829f7ec1cce76d85f5f6fbbd7f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f41c5d151078c5348271ffaf8e7410d96f2d82f8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://access.redhat.com/errata/RHSA-2026:10108'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:10996'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18134'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6570'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:9112'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-23111'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2439687'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-253495.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23111.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00489
epssPercentile: 0.39409
ingestedAt: '2026-07-03T18:53:52.422Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-09T13:07:47.429787Z'
exploits:
  github: 10
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-23111'
    - 'https://github.com/criann/check-cve-2026-23111'
    - 'https://github.com/0xBlackash/CVE-2026-23111'
  checkedAt: '2026-09-25T08:20:53.016Z'
exploitAvailable: true
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()

nft_map_catchall_activate() has an inverted element activity check
compared to its non-catchall counterpart nft_mapelem_activate() and
compared to what is logically required.

nft_map_catchall_activate() is called from the abort path to re-activate
catchall map elements that were deactivated during a failed transaction.
It should skip elements that are already active (they don't need
re-activation) and process elements that are inactive (they need to be
restored). Instead, the current code does the opposite: it skips inactive
elements and processes active ones.

Compare the non-catchall activate callback, which is correct:

  nft_mapelem_activate():
    if (nft_set_elem_active(ext, iter->genmask))
        return 0;   /* skip active, process inactive */

With the buggy catchall version:

  nft_map_catchall_activate():
    if (!nft_set_elem_active(ext, genmask))
        continue;   /* skip inactive, process active */

The consequence is that when a DELSET operation is aborted,
nft_setelem_data_activate() is never called for the catchall element.
For NFT_GOTO verdict elements, this means nft_data_hold() is never
called to restore the chain->use reference count. Each abort cycle
permanently decrements chain->use. Once chain->use reaches zero,
DELCHAIN succeeds and frees the chain while catchall verdict elements
still reference it, resulting in a use-after-free.

This is exploitable for local privilege escalation from an unprivileged
user via user namespaces + nftables on distributions that enable
CONFIG_USER_NS and CONFIG_NF_TABLES.

Fix by removing the negation so the check matches nft_mapelem_activate():
skip active elements, process inactive ones.

## Affected

- `linux_kernel >= 4.19.316, < 4.20`
- `linux_kernel >= 5.4.262, < 5.5`
- `linux_kernel >= 5.10.188, < 5.11`
- `linux_kernel >= 5.15.121, < 5.15.200`
- `linux_kernel >= 6.1.36, < 6.1.163`
- `linux_kernel >= 6.3.10, < 6.4`
- `linux_kernel >= 6.4.1, < 6.6.124`
- `linux_kernel >= 6.7, < 6.12.70`
- `linux_kernel >= 6.13, < 6.18.10`
- `linux_kernel = 6.4`
- `linux_kernel = 6.19`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.18.10`
