Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
RATHat Android Malware Leverages Gemini AI for Device Takeover
September 30, 2026
OperTraitors Tool Exposes Critical Kubernetes Privilege Escalation Paths
September 30, 2026
AI Agent Discovers Critical Linux Kernel Vulnerability CVE-2023-XXXX
September 30, 2026
Home/Vulnerabilities/AI Agent Discovers Critical Linux Kernel Vulnerability CVE-2023-XXXX
Vulnerabilities

AI Agent Discovers Critical Linux Kernel Vulnerability CVE-2023-XXXX

Key Takeaways An AI-driven security research platform, XBOW, has uncovered a high-severity vulnerability in the Linux kernel. The flaw, identified as CVE-2026-72018, allows a constrained...

Sarah simpson
Sarah simpson
September 30, 2026 4 Min Read
2 0

Key Takeaways

  • An AI-driven security research platform, XBOW, has uncovered a high-severity vulnerability in the Linux kernel.
  • The flaw, identified as CVE-2026-72018, allows a constrained out-of-bounds memory write to be leveraged for local root privilege escalation.
  • The vulnerability affects the DIBS loopback implementation within the SMC-D shared-memory communication path on standard x86 Linux systems.
  • A fix has been released, and administrators are urged to apply kernel updates immediately.

A sophisticated AI agent, part of the XBOW autonomous security research platform, has identified a critical vulnerability in the Linux kernel, designated CVE-2026-72018. This high-severity flaw enables a highly restricted out-of-bounds memory write to be escalated into full local root access, posing a significant risk to affected systems.

Table Of Content

  • Key Takeaways
  • The Obscure Origins of SMC-D and DIBS Loopback
  • Technical Details of the Vulnerability
  • Exploiting a Limited Primitive for Root Access
  • AI’s Role and Human Intervention
  • What You Should Do

The vulnerability resides within the DIBS loopback implementation, a component of the Shared Memory Communications Direct (SMC-D) path. Specifically, a missing bounds check permits an attacker to write controlled data beyond the allocated kernel buffer, creating an exploitable condition.

What makes this discovery particularly noteworthy is the inherent weakness of the initial exploit primitive. XBOW reported that the bug could reliably produce only 16 zero bytes at a partially controlled offset within kernel memory. Despite this severe limitation, researchers successfully crafted a local privilege escalation exploit that achieved root access without requiring a separate information leak.

The Obscure Origins of SMC-D and DIBS Loopback

The issue stems from the dibs_loopback driver, which facilitates SMC-D on standard x86 Linux systems, bypassing the need for IBM Z hardware. Historically, SMC-D was primarily associated with IBM mainframe environments and specialized Internal Shared Memory (ISM) devices. This niche application meant its codebase received comparatively less scrutiny from a security perspective.

The introduction of the dibs_loopback virtual device changed this landscape. By making SMC-D accessible on commodity Linux systems via loopback networking, code that was once considered difficult to reach transformed into a local attack surface, increasing its exposure to potential vulnerabilities.

Technical Details of the Vulnerability

XBOW’s analysis revealed that a peer-controlled dmbe_idx value could manipulate offset calculations during the SMC connection setup. This manipulated offset eventually reached the move_data() routine within the DIBS loopback driver, which then executed a memcpy() operation without adequately validating whether the provided offset and write size remained within the bounds of the destination buffer.

The upstream remediation addresses this by adding validation for both the offset and size parameters prior to the copy operation. Linux advisory information describes the flaw as an out-of-bounds write capable of corrupting memory beyond the allocated buffer, primarily because software loopback implementations lack the hardware-enforced memory region protections found in actual ISM hardware.

Exploiting a Limited Primitive for Root Access

The local attack scenario necessitates the CAP_NET_ADMIN capability. XBOW leveraged this capability to enable SMC-D functionality and manipulate loopback CLC handshake traffic. This was achieved through an NFQUEUE-based man-in-the-middle setup, allowing the researchers to intercept and modify specific handshake fields.

By altering these fields, the exploit could force a precise out-of-bounds write into adjacent kernel memory. Crucially, this was not an arbitrary write; it was a fixed 16-byte zero write, positioned at a chosen alignment over a limited range. Instead of attempting to develop a more powerful primitive, the researchers strategically targeted the Linux kernel’s cred structure.

The cred structure stores a process’s user and group identity fields. When the 16 zero bytes landed on fields within this structure, including the effective user ID (euid), the euid value became zero. Since Linux permission checks treat an effective UID of zero as root, the compromised process could then establish a full root identity and spawn a root shell.

This exploitation strategy underscores a critical lesson in vulnerability research: even a highly restricted write primitive can be security-critical if it can zero out sensitive security-related state, making it sufficient for privilege escalation.

XBOW reported that their proof-of-concept exploit achieved success on 22 out of 100 separate boots, with the first successful privilege escalation occurring on the seventh boot. The experiment was conducted on Ubuntu 24.04 running Linux 7.1.0-rc6 with kernel mitigations disabled, suggesting that real-world reliability may vary depending on distributions, kernel builds, allocator behavior, and enabled mitigations.

The CVE record for CVE-2026-72018 carries a CVSS 3.1 base score of 7.8, classifying it as High severity. It features a local attack vector, requires low privileges, demands no user interaction, and has a high impact on confidentiality, integrity, and availability.

AI’s Role and Human Intervention

XBOW stated that its AI agent managed various aspects of the research process, including threat modeling, code auditing, bug discovery, validation, and a substantial portion of exploit development. However, human researchers played a vital role through several key interventions.

These interventions included redirecting the system toward a local privilege escalation model, encouraging it to reconsider packet interception after initial dismissal, and requiring experimental validation of the restricted zero-write behavior. Researchers also guided the agent to exploit the existing primitive directly rather than pursuing a more complex use-after-free or arbitrary-write chain.

These findings highlight both the immense potential and current limitations of autonomous vulnerability research. While AI systems excel at exhaustive code analysis and testing across obscure subsystems, human judgment remains crucial for evaluating complex attack paths, correcting outdated assumptions, and refining exploit strategies.

What You Should Do

  • Immediately apply Linux kernel updates that include the DIBS loopback bounds-check fix.
  • Reboot all affected systems after applying the patches to ensure the fix is fully active.
  • Review all workloads and containers that have been granted the CAP_NET_ADMIN capability, as this privilege is central to the demonstrated local attack path. Reduce its scope where possible.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical RCE in Unsloth Studio Lets Malicious Hugging Face Models Execute Code

Next Post

OperTraitors Tool Exposes Critical Kubernetes Privilege Escalation Paths

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Launches Codex Security Cloud for Always-On App Security
September 30, 2026
Critical OAuth Flaw in Microsoft Copilot Python SDK Exposes AI Agent Accounts
September 30, 2026
Critical Octopus Server Flaw CVE-2023-31446 Allows Remote Code Execution
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us