CVE-2026-31431: Linux Kernel LPE — Root Access via Netfilter UAF, Active Exploitation Confirmed

Technical exploit walkthrough of the Linux kernel Netfilter use-after-free vulnerability enabling local root privilege escalation.

CVE-2026-31431: Linux Kernel LPE — Root Access via Netfilter UAF, Active Exploitation Confirmed
📌
Security Roundup Series: Week of May 14, 2026 • 4 min read deep dive
⚠️
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-31431 Severity: CVSS 7.8 Status: CISA KEV Addition Target Component: Linux Kernel Netfilter Subsystem (nf_tables)

CISA added CVE-2026-31431 to its Known Exploited Vulnerabilities catalog this week, confirming active exploitation of a local privilege escalation vulnerability in the Linux kernel that allows an unprivileged local user to obtain root access. With CVSS 7.8, it is not the most spectacular vulnerability of the week, but its presence on the KEV list and confirmed in-the-wild exploitation make it a priority patch for any Linux-based infrastructure, containers, or developer workstations.

Vulnerability Overview

CVE-2026-31431 is a use-after-free vulnerability in the Linux kernel's netfilter subsystem (nf_tables). A local unprivileged user can exploit the UAF condition to overwrite kernel memory and escalate privileges to root. The vulnerability is reachable from unprivileged user namespaces, meaning container escape is possible in environments where user namespaces are enabled (the default on most modern Linux distributions).

CVSS v3.1: 7.8 (High) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploitation Path

// Simplified conceptual PoC — illustrates the UAF trigger
// Actual PoC involves nf_tables set/rule manipulation

// 1. Create nft rule referencing an object
nft add table ip mytable
nft add chain ip mytable mychain
nft add rule ip mytable mychain counter   // creates object reference

// 2. Delete the referenced object (triggers the UAF)
nft delete chain ip mytable mychain       // frees the object

// 3. Spray the freed memory with controlled data
//    (timing-dependent; requires racing the allocator)

// 4. Dereference the dangling pointer via saved rule
//    -> controlled kernel write -> overwrite modprobe_path
//    -> next kernel module load runs attacker binary as root

// Full PoC: refs in Qualys blog post and LWN thread on fix commit

Container escape angle: In cloud and Kubernetes environments where pods run as non-root but with user namespace privileges, an attacker who achieves code execution inside a container (e.g., via a web application vulnerability) can use CVE-2026-31431 to escalate within the container and then escape to the host if the container shares the host kernel — which is standard for Docker and containerd-based runtimes.

Affected Kernel Versions

Vulnerable: Linux kernel 5.15 through 6.8.x (all distributions)

Fixed versions (upstream):
  6.8.y: linux-6.8.11 (stable)
  6.6.y (LTS): linux-6.6.32
  6.1.y (LTS): linux-6.1.93
  5.15.y (LTS): linux-5.15.162

Distribution patches (check your distro's security tracker):
  Ubuntu:  USN-7089-1 (focal/jammy/noble)
  Debian:  DSA-5702-1
  RHEL 9:  RHSA-2026:3441
  RHEL 8:  RHSA-2026:3442
  Amazon Linux 2023: ALAS-2026-2318

Remediation

# 1. Check your current kernel version
uname -r

# 2. Update kernel (distribution-specific)

# Ubuntu / Debian
apt update && apt install --only-upgrade linux-image-$(uname -r)
# Then reboot: reboot

# RHEL / CentOS / Amazon Linux
yum update kernel
# Then reboot: reboot

# 3. If immediate reboot is not possible — WORKAROUND:
#    Disable unprivileged user namespaces (breaks some container workflows)
sysctl -w kernel.unprivileged_userns_clone=0
echo "kernel.unprivileged_userns_clone=0" >> /etc/sysctl.d/99-security.conf

# 4. For container environments — validate user namespace settings
#    Verify your CRI (containerd/cri-o) does NOT pass --userns-remap
#    unless you've applied the kernel patch

# 5. Verify patch applied:
grep "CVE-2026-31431\|ALAS-2026-2318\|USN-7089" /var/log/dpkg.log
# or
rpm -q --changelog kernel | grep "CVE-2026-31431" 

Detection — Exploitation Attempts

Audit syscall monitoring (auditd):
  -a always,exit -F arch=b64 -S unshare -k user_namespace_creation
  -a always,exit -F arch=b64 -S clone -F a0=0x10000000 -k user_namespace_clone

Falco rule:
  - rule: Suspicious nftables manipulation
    condition: >
      syscall.type = write AND fd.name contains "nft" AND
      user.uid != 0 AND not proc.name in (allowed_nft_procs)
    output: "Potential CVE-2026-31431 exploitation (user=%user.name cmd=%proc.cmdline)"

Sysdig / eBPF:
  sysdig "evt.type=openat and fd.name contains nf_tables and user.uid != 0" 

→ Read the full weekly roundup: Security Roundup — Week of May 14, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther