cbcvebase.
CVE-2026-23111
published 2026-02-13

CVE-2026-23111: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.7th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don't need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones. Compare the non-catchall activate callback, which is correct: nft_mapelem_activate(): if (nft_set_elem_active(ext, iter->genmask)) return 0; /* skip active, process inactive */ With the buggy catchall version: nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */ The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain->use reference count. Each abort cycle permanently decrements chain->use. Once chain->use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free. This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES. Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 25aa2ad37c2162be1c0bc4fe6397f7e4c13f00f8 < 8c760ba4e36c750379d13569f23f5a6e185333f58c760ba4e36c750379d13569f23f5a6e185333f5
linuxlinux>= 4.19.316 < 4.204.20
linuxlinux>= 5.10.188 < 5.115.11
linuxlinux>= 5.15.121 < 5.15.2005.15.200
linuxlinux>= 5.4.262 < 5.55.5
linuxlinux>= 6.1.36 < 6.1.1636.1.163
linuxlinux>= 6.3.10 < 6.46.4
linuxlinux>= 628bd3e49cba1c066228e23d71a852c23e26da73 < 42c574c1504aa089a0a142e4c13859327570473d42c574c1504aa089a0a142e4c13859327570473d
linuxlinux>= 628bd3e49cba1c066228e23d71a852c23e26da73 < 1444ff890b4653add12f734ffeffc173d42862dd1444ff890b4653add12f734ffeffc173d42862dd
linuxlinux>= 628bd3e49cba1c066228e23d71a852c23e26da73 < 8b68a45f9722f2babe9e7bad00aa74638addf0818b68a45f9722f2babe9e7bad00aa74638addf081
linuxlinux>= 628bd3e49cba1c066228e23d71a852c23e26da73 < f41c5d151078c5348271ffaf8e7410d96f2d82f8f41c5d151078c5348271ffaf8e7410d96f2d82f8
linuxlinux>= d60be2da67d172aecf866302c91ea11533eca4d9 < b9b6573421de51829f7ec1cce76d85f5f6fbbd7fb9b6573421de51829f7ec1cce76d85f5f6fbbd7f
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.