AI agent uncovers Linux kernel bug that can grant root

Published

An autonomous AI agent built by security firm XBOW has found a memory-safety bug in the Linux kernel that, in XBOW's own tests, let a local process turn itself into root. The flaw, tracked as CVE-2026-72018, sits in a little-known shared-memory networking path, and the research is as notable for what the AI could not do on its own as for what it did.

The details come from XBOW's research, as summarised in a threat advisory published by Rewterz. The bulletin rates the flaw High severity, with a local attack vector, low privileges required, no user interaction, and high impact to confidentiality, integrity and availability. It does not give a numeric CVSS score, and it does not report exploitation in the wild.

A mainframe feature that reached ordinary x86 servers

The bug lives in the DIBS loopback driver (dibs_loopback), which backs SMC-D, a shared-memory communication mode historically tied to IBM mainframes and their internal shared-memory devices. The dibs_loopback virtual device made that functionality available on standard x86 Linux systems with no IBM Z hardware, which widened the code's exposure to local attackers.

According to the research, a peer-controlled value called dmbe_idx can influence offset calculations during SMC connection setup. That value eventually reaches a routine named move_data(), where a memcpy() copies data without checking the destination's boundaries, so attacker-controlled data lands beyond an allocated kernel buffer.

Sixteen zero bytes were enough for root

The primitive the researchers obtained was tightly restricted: a 16-byte write of zeros at a partly controlled kernel memory location. It turned out to be enough. The exploit aimed the write at the kernel's cred structure, which records a process's identity, and zeroed the effective user ID (euid). Linux treats a UID of zero as root, so the process could take on a root identity and spawn a root shell.

The demonstrated attack is not trivial to reach. It requires the CAP_NET_ADMIN capability, which the researchers used to enable SMC-D and to manipulate loopback CLC handshake traffic through an NFQUEUE-based interception setup. XBOW reported a successful privilege escalation on 22 of 100 boots, with the first success on the seventh boot. Testing ran on Ubuntu 24.04 with Linux 7.1.0-rc6 and kernel mitigations disabled, so reliability on production builds with their usual hardening may differ.

The AI did the legwork, humans steered it

XBOW's agent handled threat modelling, code auditing, discovery, validation and much of the exploit development. But the research also records where people had to step in: redirecting the agent toward local privilege escalation, getting it to revisit a packet-interception approach it had initially discarded, experimentally validating the zero-write primitive, and keeping it focused on that primitive rather than chasing a more complex arbitrary-write or use-after-free chain.

The finding adds to the debate over AI-driven bug hunting covered in Google's recent findings on exploitation in the AI era, and it arrives in a year when Linux kernel flaws have repeatedly landed on CISA's exploited list.

Patch the kernel, then audit CAP_NET_ADMIN

Administrators should install Linux kernel updates that include the DIBS loopback bounds-check fix, then reboot so the patched kernel is actually running. The advisory does not list fixed kernel versions, so check your distribution's security tracker for CVE-2026-72018. Because CAP_NET_ADMIN is central to the demonstrated path, review which systems, workloads and containers hold that capability and remove it wherever it is not needed. Teams with no use for SMC-D should assess whether the dibs_loopback driver needs to be present at all, and monitor for unusual SMC-D or loopback networking activity alongside signs of kernel-level privilege escalation.

The bug itself is a familiar shape: a missing bounds check ahead of a memory copy. What has changed is who found it. When an agent can work through an obscure kernel subsystem end to end with only a few human nudges, the cost of auditing rarely examined code falls, and that cuts both ways.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions