Security R&D at Miggo | eBPF, Tracing, OS | Jibril Runtime Creator | Former Tracee Runtime Security Maintainer, Ubuntu Core Dev and Mainframer.
Joined June 2019
This is part two of a series (medium.com/@miggo-enginee…). Part one was about detecting CopyFail and DirtyFrag (medium.com/@miggo-enginee…) - if you missed it, same idea applies here. CVE-2026-23111 is a use-after-free in nf_tables, reachable from an unprivileged user namespace. The
“Detecting the nftables Catchall Use-After-Free (CVE-2026–23111) by thinking outside the box” by Miggo Engineering medium.com/@miggo-enginee…

