XBOW reported finding and exploiting CVE-2026-72018, a high-severity out-of-bounds write in Linux’s DIBS loopback implementation for the SMC-D shared-memory communications path. A missing bounds check during a driver copy operation lets peer-controlled CLC handshake data trigger a constrained 16-byte zero write at a partly controlled kernel-memory address; XBOW developed this seemingly limited primitive into local root access by zeroing security-relevant fields in the kernel cred structure, including the effective UID.
The demonstrated exploit requires CAP_NET_ADMIN to enable SMC-D and manipulate handshake traffic through an NFQUEUE-based man-in-the-middle setup, limiting exposure to attackers with substantial local privileges. The finding, which human reviewers had missed, highlights the growing role of AI-assisted vulnerability research while retaining human judgment in the exploitation process. Upstream fixes now validate the offset and copy size before the vulnerable operation; administrators should apply the relevant kernel updates, reboot affected hosts, and review assignments of CAP_NET_ADMIN.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-72018 was assigned and publicly released after XBOW reported the Linux kernel DIBS loopback out-of-bounds write and maintainers approved a patch.
Upstream remediation added validation of the offset and copy size before the vulnerable DIBS loopback copy operation. Administrators were advised to apply Linux kernel updates containing the fix and reboot affected systems.
XBOW reported finding CVE-2026-72018 in the Linux kernel's DIBS loopback implementation and demonstrated local privilege escalation to root. The flaw enables a constrained 16-byte zero write that XBOW used to zero security-relevant fields, including euid, in a kernel cred structure; the demonstrated path requires CAP_NET_ADMIN.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourcexbow.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.