tech

High-severity vulnerability in Linux caused by a single faulty character

Use-after-free bug can be exploited to evade sandbox defenses.

High-severity vulnerability in Linux caused by a single faulty character

TL;DR

  • A high-severity vulnerability (CVE-2026-23111) has been discovered in the Linux kernel's nf_tables subsystem.
  • The bug, caused by a single erroneous exclamation point, leads to a use-after-free condition.
  • An unprivileged user can exploit this vulnerability to escalate their system rights to root.
  • The exploit disrupts the deletion of verdicts within the nf_tables framework, allowing for arbitrary memory manipulation.
  • The vulnerability was fixed in the kernel in February and has been backported to major Linux distributions.
  • Security firms Exodus Intelligence and FuzzingLabs have demonstrated proof-of-concept exploits.
  • This vulnerability can be chained with other exploits to evade operating system security defenses.