1 link tagged with all of: linux + container-escape + nf_tables + kernel-exploit
Click any tag below to further narrow down your results
Links
Researchers published a local root exploit for CVE-2026-23111 in nf_tables, letting unprivileged users escape containers and gain host root. The fix was a one-line patch in February; update kernels or disable unprivileged user namespaces if you haven’t.
- A one-character inverted check in nf_tables (CVE-2026-23111) allows unprivileged users to escalate to root, patched upstream in February but publicly exploited by Exodus Intelligence and FuzzingLabs in April/June.
- Most major distros (Ubuntu, Debian, Red Hat) shipped vulnerable kernels with unprivileged user namespaces enabled by default, rated CVSS 7.8.
- Until systems are patched and rebooted, disabling unprivileged user namespaces is the recommended mitigation.
- This flaw is part of a broader wave of recent local-root exploits (Copy Fail, Dirty Frag, Fragnesia, DirtyDecrypt, a nine-year-old ptrace bug), which Synacktiv attributes partly to AI-aided vulnerability discovery.