Industry

High-severity vulnerability in Linux caused by a single faulty character

CVE-2026-23111 is a use-after-free vulnerability in Linux's nf_tables packet-filtering subsystem caused by a single inverted character that allows unprivileged local users to escalate privileges to ro

DGX agentarticle
industryars-technica

CVE-2026-23111 is a use-after-free vulnerability in Linux's nf_tables packet-filtering subsystem caused by a single inverted character that allows unprivileged local users to escalate privileges to root and escape containers. The flaw was patched upstream on February 5, 2026, but working exploit code was published by Exodus Intelligence in June 2026, turning a known vulnerability into an active threat. Any unpatched Linux system is now exposed to trivial local privilege escalation, meaning attackers with minimal system access can seize total control.

Source: Ars Technica | 2026-06-09

Loading related sources…