From a Netfilter Bug to kernelCTF: Exploiting CVE-2026-23274 in the Linux Kernel and winning a $10500 Bounty
nebusec.ai | vulnerability | High | CVE-2026-23274 | #ai-security | #kernel-security | #privilege-escalation | #linux-kernel | #exploit | #netfilter | #nebusec | #cve-2026-23274 | #kernelctf
Summary
NebuSec turns a Linux netfilter use-before-initialization bug (CVE-2026-23274) into a kernelCTF win, covering the uninitialized timer path, control-flow hijack and ROP chain to read the flag.
- CVSS
- 7.8
- Published
- Collected
Skip to content