Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access.

The flaw affects the DIBS loopback implementation used by the SMC-D shared-memory communication path, where a missing bounds check allows attacker-controlled data to be copied beyond an allocated kernel buffer.

The vulnerability is notable not only for its impact, but for the weakness of the available exploit primitive. XBOW’s research showed that the bug could reliably produce only 16 zero bytes at a partly controlled kernel-memory offset.

Despite this limitation, the researchers developed a local privilege-escalation exploit that elevated a process to root without requiring a separate information leak.

The issue exists in the dibs_loopback driver, which enables Shared Memory Communications Direct, or SMC-D, on standard x86 Linux systems without IBM Z hardware.

SMC-D was historically associated with IBM mainframe environments and Internal Shared Memory devices, leaving much of its code comparatively less scrutinized.

The exploit reaching a shell as root (source: Xbow)

Adding the dibs_loopback virtual device changed that exposure. It made SMC-D reachable on commodity Linux systems through loopback networking, turning code once considered difficult to access into a local attack surface.

AI Agent Finds Linux Kernel Bug

XBOW found that a peer-controlled dmbe_idx value could influence offset calculations during SMC connection setup. That offset eventually reached the move_data() routine in the DIBS loopback driver, which performed a memcpy() operation without validating whether the supplied offset and write size remained within the destination buffer.

The upstream remediation adds validation for offset and size before the copy operation. Linux advisory information describes the flaw as an out-of-bounds write that could corrupt memory beyond the allocated buffer because software loopback lacks the hardware-enforced memory-region protections available in real ISM hardware.

The CLC handshake (Proposal, Accept, Confirm) and the peer-controlled fields the kernel must validate  (source : xbow)
The CLC handshake (Proposal, Accept, Confirm) and the peer-controlled fields the kernel must validate (source: Xbow)

The local attack scenario requires CAP_NET_ADMIN. XBOW used that capability to enable SMC-D functionality and manipulate loopback CLC handshake traffic through an NFQUEUE-based man-in-the-middle setup.

By modifying selected handshake fields, the exploit could force an out-of-bounds write into adjacent kernel memory. The usable effect was not an arbitrary write: it was a fixed 16-byte zero write positioned at a chosen alignment over a limited range.

Rather than attempting to build a more powerful primitive, researchers targeted the Linux kernel’s cred structure, which stores a process’s user and group identity fields.

If zero bytes land on fields including euid, the effective user ID becomes zero. Since Linux permission checks treat an effective UID of zero as root, the affected process can subsequently establish a full root identity and spawn a root shell.

This approach demonstrates a familiar exploitation lesson: a primitive does not need to be arbitrary to be security-critical. If a restricted write can zero security-sensitive state, it may still be sufficient for privilege escalation.

XBOW reported that its proof of concept succeeded on 22 out of 100 separate boots, with the first successful privilege escalation appearing on the seventh boot.

16 zero-bytes overwrite cred, zeroing euid and granting root privileges  (source : xbow)
16 zero-bytes overwrite cred, zeroing euid and granting root privileges (source: Xbow)

The experiment was performed on Ubuntu 24.04 using Linux 7.1.0-rc6 with kernel mitigations disabled, so that real-world reliability may differ across distributions, kernel builds, allocator behavior, and enabled mitigations.

The CVE record carries a CVSS 3.1 base score of 7.8, rated High, with a local attack vector, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.

XBOW said its agent handled threat modeling, code auditing, bug discovery, validation, and much of the exploit-development process.

However, human researchers made several important interventions. They redirected the system toward a local privilege-escalation model, encouraged it to revisit packet interception after it initially discarded that option, and required it to validate the restricted zero-write behavior experimentally.

Researchers also pushed the agent to exploit the existing primitive directly rather than spending time seeking a more powerful use-after-free or arbitrary-write chain.

The findings highlight both the promise and current limits of autonomous vulnerability research. AI systems can sustain exhaustive code analysis and testing across obscure subsystems.

However, human judgment can still be decisive when evaluating costly attack paths, correcting stale assumptions, and reframing an exploit strategy.

Administrators should apply Linux kernel updates containing the DIBS loopback bounds-check fix and reboot affected systems. Organizations should also review workloads and containers granted CAP_NET_ADMIN, because that capability is central to the demonstrated local attack path.