Linux Kernel CVE-2026-72018 Can Give Local Users Root
XBOW disclosed CVE-2026-72018, a local Linux SMC-D out-of-bounds write that can give CAP_NET_ADMIN processes root.
XBOW, described as an autonomous security research platform or AI agent, disclosed CVE-2026-72018, a high-severity out-of-bounds write in the Linux kernel dibs_loopback driver used by SMC-D. Both reports say a local process that already holds CAP_NET_ADMIN can reach root under favorable conditions and that the flaw is not remotely exploitable. GBHackers describes an unchecked copy in move_data(), while Cyber Security News specifies a missing bounds check that writes 16 zero bytes past a kernel buffer and was used to clear credential fields such as euid. A published proof of concept succeeded on 22 of 100 boots on Ubuntu 24.04 running Linux 7.1.0-rc6 with mitigations disabled. Cyber Security News rates the issue CVSS 3.1 7.8 and says the upstream fix validates offset and size before memcpy. GBHackers cites Red Hat warnings of memory corruption, denial of service, or code execution, and lists kernels 6.12.97, 6.18.40, and 7.1.5 or later as unaffected. The reports are consistent; the second is more specific about write size, score, and the fix.
- XBOW disclosed CVE-2026-72018, a high-severity out-of-bounds write in the Linux kernel dibs_loopback driver used by SMC-D.
- Exploitation is local and requires CAP_NET_ADMIN; both reports say it is not remote.
- Cyber Security News describes a missing bounds check that writes 16 zero bytes past a kernel buffer and can clear credential fields such as euid; GBHackers describes an unchecked copy in move_data().
- A local proof of concept gained root in 22 of 100 boots on Ubuntu 24.04 with Linux 7.1.0-rc6 and mitigations disabled.
- Cyber Security News assigns CVSS 3.1 a score of 7.8 and says the upstream fix checks offset and size before memcpy.
- Red Hat warned of memory corruption, denial of service, or code execution.
- Kernels 6.12.97, 6.18.40, and 7.1.5 or later are listed as unaffected.
Coverage timelineoldest first · each row is one article
- · 16h agoLinux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access
GBHackers· 66
CVE-2026-72018 lets local CAP_NET_ADMIN users escalate to root through a Linux SMC-D out-of-bounds write.
- · 15h agoAI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access
Cyber Security News· 67
XBOW disclosed CVE-2026-72018, a Linux kernel DIBS flaw that turns a 16-byte zero write into local root.
Vulnerabilities in this storyAll →
- CVE-2026-720187.8<1%Linux kernel: dibs: loopback: validate offset and size in move_data()published · Linux kernel PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-72018 | Linux kernel: dibs: loopback: validate offset and size in move_data() |