One Bad Character Breaks the Whole Fence: Linux Kernel Flaw Hands Wolves the Gate Key
I have been saying this for thirty years. Thirty. Years.
One character. One single, solitary misplaced character in the kernel's nf_tables packet-filtering code, and suddenly any unprivileged local user can waltz straight to root. Full escalation. Container escape. The whole catastrophe. CVE-2026-23111, for those of you keeping a dossier, which you absolutely should be.
The hole in the fence was patched upstream on February 5th. Exodus Intelligence then published a complete, working technical walkthrough on June 8th. That is four months of quiet, followed by a detailed map handed directly to every wolf on the internet. Wonderful. Truly wonderful work, everyone.
Now, I want to be precise about what "use-after-free" means in practical terms for the flock. The kernel grabbed a piece of memory, finished with it, and then kept using it anyway, like a shepherd who throws away the gate latch but still expects the gate to hold. Any sufficiently motivated wolf can stuff something nasty into that freed memory and wait for the kernel to come back and execute it. On their behalf. With root privileges.
In my day, we ran critical processes on isolated machines with no network connection and physical guards at the door. You want to escalate privileges? You need a ladder and a very good reason. Nobody was publishing "working exploits" in a blog post with diagrams.
The Sky Pasture crowd should be paying particular attention. Container isolation is only as good as the kernel underneath it. If the kernel is compromised, your containers are decorative. They are little wool hats on a wolf.
The Shepherds, naturally, will read this headline, nod gravely, and ask if it affects the quarterly dashboard. It does not affect the dashboard. It affects everything below the dashboard.
Remediation
First. Update your Linux kernel. Immediately. The upstream patch has existed since February. If your systems are still unpatched, I do not want to hear your reasons.
Second. Audit who has local access to your systems. Unprivileged local users are the threat vector here. If your flock has more local accounts than you can name, that is its own emergency.
Third. Deploy kernel exploit mitigations where available. Seccomp profiles, SELinux, AppArmor. Yes, they are imperfect. They are also significantly better than nothing, which is what you currently have.
Fourth. If you are relying on container isolation as a security boundary without validating the kernel underneath, please sit down and think about what you have done.
Patch early, patch often, and for the love of magnetic tape, stop trusting the Sky Pasture to sort this out for you.
Victor Woolridge, still right, still ignored.
Original Report: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html