EGI SVG Advisories

Advisory-EGI-SVG-2026-23

CRITICAL risk Linux vulnerability via nf_tables

Updated: 2026-07-21 Date: 2026-06-10

CRITICAL risk vulnerability concerning the Linux kernel’s nf_tables component which can be used to achieve privilege escalation. Public exploits have been published.

IDs AND CVSS SCORE

EGI SVG ID : EGI-SVG-2026-23

CVE ID : CVE-2026-23111

CVSS 3.X Scores :

ACTIONS REQUIRED/RECOMMENDED

Urgent action may be needed on hosts that allow shell or container access by unprivileged users and have NOT been rebooted with a recently released kernel, but are instead relying on mitigation against previous vulnerabilities (e.g. EGI-SVG-2026-{12,14,15,17,21}). Such hosts should either be rebooted with a recent kernel or need to have further mitigation applied, see below.

In general, we advise sites to update and reboot affected hosts as soon as practically feasible, instead of just relying on mitigation for a long time.

All affected resources MUST be either patched or have mitigation in place or be made inaccessible by 2026-06-18 00:00 UTC.

MITIGATION

To prevent exploitation of the given vulnerability, it is sufficient to disable unprivileged network namespaces: please see [R 8] for details.

STATUS OF THIS ADVISORY

TLP:CLEAR information - Unlimited distribution

https://advisories.egi.eu/Advisory-EGI-SVG-2026-23

https://advisories.egi.eu/Advisory-SVG-CVE-2026-23111

Minor updates may be made without re-distribution to the sites.

CONTACT AND OTHER INFORMATION ON SVG


This advisory is subject to the Creative Commons licence 
https://creativecommons.org/licenses/by/4.0/ and
the EGI (https://www.egi.eu/) Software Vulnerability Group 
must be credited. ----

See [R 99]

REFERENCES

CREDITS

SVG was alerted to this vulnerability by Sven Gabriel