Updated: 2026-07-21 Date: 2026-06-10
CRITICAL risk vulnerability concerning the Linux kernel’s nf_tables component which can be used to achieve privilege escalation. Public exploits have been published.
EGI SVG ID : EGI-SVG-2026-23
CVE ID : CVE-2026-23111
CVSS 3.X Scores :
Urgent action may be needed on hosts that allow shell or container access by unprivileged users and have NOT been rebooted with a recently released kernel, but are instead relying on mitigation against previous vulnerabilities (e.g. EGI-SVG-2026-{12,14,15,17,21}). Such hosts should either be rebooted with a recent kernel or need to have further mitigation applied, see below.
In general, we advise sites to update and reboot affected hosts as soon as practically feasible, instead of just relying on mitigation for a long time.
All affected resources MUST be either patched or have mitigation in place or be made inaccessible by 2026-06-18 00:00 UTC.
To prevent exploitation of the given vulnerability, it is sufficient to disable unprivileged network namespaces: please see [R 8] for details.
TLP:CLEAR information - Unlimited distribution
https://advisories.egi.eu/Advisory-EGI-SVG-2026-23
https://advisories.egi.eu/Advisory-SVG-CVE-2026-23111
Minor updates may be made without re-distribution to the sites.
This advisory is subject to the Creative Commons licence
https://creativecommons.org/licenses/by/4.0/ and
the EGI (https://www.egi.eu/) Software Vulnerability Group
must be credited. ----
See [R 99]
[R 4] https://security-tracker.debian.org/tracker/CVE-2026-23111
[R 6] https://errata.build.resf.org/ (RockyLinux)
[R 7] https://errata.almalinux.org/ (AlmaLinux)
[R 8] https://csirt.egi.eu/2022/10/19/linux-namespaces-and-containers/
[R 99] https://confluence.egi.eu/display/EGIBG/SVG+Advisories
SVG was alerted to this vulnerability by Sven Gabriel