AI Agent Uncovers Linux Kernel Vulnerability Allowing Root Access

Security researchers have revealed a high-severity flaw in the Linux kernel, tracked as CVE-2026-72018, that allows an unprivileged local attacker to gain root privileges through a tightly constrained memory write vulnerability. The issue arises within the DIBS loopback implementation of Shared Memory Communications Direct (SMC-D), which lacks proper bounds checking, enabling controlled data to overflow a kernel buffer. This discovery emerged through the work of autonomous security platform XBOW.

How the Bug Works

The vulnerability resides in the dibs_loopback driver, which implements SMC-D on standard x86 Linux systems without IBM Z hardware. Normally associated with mainframes, SMC-D’s recent inclusion in loopback networking lowered its barrier to exploitation. The flaw permits peer-controlled manipulation of an offset tied to a move_data routine, where memcpy copies data without ensuring the offset and length stay inside the destination buffer.

The exploit primitive that the AI agent identified is deceptively limited: it can reliably write exactly 16 zero bytes at a partially controlled offset in kernel memory. No arbitrary write or large-scale memory corruption is possible under default conditions. Yet this limited write proved enough—when it landed on sensitive fields in the kernel’s cred structure, it zeroed effective user ID values, thereby granting root privileges.

Attack Conditions, Reliability, and Scores

To pull off the exploit, the attacker must already possess CAP_NET_ADMIN privileges. Using that, researchers set up a man-in-the-middle using NFQUEUE to intercept CLC handshake packets from the SMC-D loopback driver, altering select fields to trigger the out-of-bounds write. Though the exploit only writes 16 zero bytes, targeting credential fields culminates in immediate privilege escalation.

Testing was done on Ubuntu 24.04 with Linux kernel version 7.1.0-rc6, with kernel mitigations disabled. Under these conditions, the proof-of-concept achieved root on 22 of 100 boots, with the first success occurring on boot seven. Across different systems—depending on kernel build, protections, and allocator behavior—real-world reliability may vary.

Severity scores reflect the risk: the vulnerability has been rated 7.8 under CVSS 3.1 rules, categorizing it as “High.” Key factors in the rating include local attack vector, no user interaction required, and high confidentiality, integrity, and availability impact.

Human and AI in the Loop

Though an autonomous AI platform identified the flaw—from threat modeling through exploit development—human researchers played integral roles. They steered the strategy toward local privilege escalation, revisited attack paths initially dismissed by the agent, and validated experimentally that the zero-write primitive was effective. This blend of AI scale and human insight proved essential.

What to Do: Mitigations and Best Practices

Kernel code has been updated upstream to enforce bounds checking on both offset and size before the unsafe memcpy call. Systems running affected kernels must apply these updates and reboot. Any host that enables the dibs_loopback device or grants CAP_NET_ADMIN should be considered exposed. Auditing containers and workloads for excessive privileges becomes crucial, as does ensuring kernel mitigations are active.

This incident illustrates both what AI vulnerability research can achieve and where it falls short. AI agents excel at scanning obscure code paths, generating exploit primitives for edge cases. But human oversight remains vital—identifying meaningful strategies, correcting mistaken assumptions, validating practical exploit success. For defenders, this foreshadows a future where AI-driven offense may outpace detection, unless patching velocity and privilege hygiene improve. Keep systems updated, enforce least privilege, and don’t let AI’s reach lull you into complacency.