---
schema: 1
kind: research
title: Exodus Intelligence publishes working exploit for a one-character Linux kernel nf_tables use-after-free (CVE-2026-23111)
headline: Exodus Intelligence publishes working exploit for a one-character Linux kernel nf_tables use-after-free (CVE-2026-23111)
summary: "Working public exploit for a one-character Linux kernel nf_tables UAF (CVE-2026-23111) — >99% reliable local-root and container escape across mainstream distros; patch shipped upstream 5 February (Exodus Intelligence, 2026-06-08)."
discovered_at: "2026-06-09T05:00:06Z"
event_date: 2026-06-08
run_id: 2026-06-09-40d562df
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - priv-esc
  - poc-public
regions:
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-23111
    cvss: "7.8"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/"
    publisher: Exodus Intelligence write-up
    role: primary
  - url: "https://ubuntu.com/security/CVE-2026-23111"
    publisher: Ubuntu Security tracker
    role: corroborating
  - url: "https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html"
    publisher: The Hacker News
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Apply kernel updates for CVE-2026-23111 and harden container syscall policy** — a >99%-reliable public LPE/container-escape exploit is now available; ship the 5 February upstream fix and enforce seccomp/AppArmor restrictions on `nf_tables` for untrusted workloads."
migrated_from: briefs/2026-06-09.md
---

Exodus Intelligence released a full technical write-up and working exploit for CVE-2026-23111, a use-after-free in the Linux kernel `nf_tables` subsystem caused by a single misplaced `!` operator in `nft_map_catchall_activate()` that inverts the `genmask` check and skips inactive catchall elements during the abort path ([Exodus Intelligence, 2026-06-08](https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/)). Exodus reports >99% reliability on idle Debian Bookworm/Trixie and Ubuntu 22.04/24.04 LTS, yielding unprivileged-local-user to root escalation and container escape (T1068, T1611) ([The Hacker News, 2026-06-08](https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html)). The flaw was patched upstream on 5 February 2026; distro packages are shipping the fix ([Ubuntu Security](https://ubuntu.com/security/CVE-2026-23111), rated 7.8). No network-reachable path exists — exploitation requires local access or code execution inside a container, making this high-value post-exploitation tooling for shared compute (Kubernetes nodes, CI/CD runners, multi-tenant VMs).

**Why it matters to us:** With a reliable public exploit now available, the patch gap is the exposure. Apply vendor kernel updates containing the 5 February upstream fix; in container environments enforce seccomp and AppArmor/SELinux profiles that restrict `nf_tables` syscalls for untrusted workloads. Detection concepts: anomalous UID transitions to 0 from non-root parents (Linux audit `execve`/`setuid` records); unexpected privileged process spawns inside containers.
