Back to News
RSS feedxbow.com

XBOW Finds and Exploits Linux Kernel LPE CVE-2026-72018

Summary

XBOW reports discovering and validating CVE-2026-72018, an out-of-bounds write in the Linux kernel's SMC-D loopback path that can be triggered by a user with CAP_NET_ADMIN and used for local privilege escalation. The vulnerable path trusted peer-controlled SMC fields, including dmbe_idx and dmbe_size, to calculate a buffer offset without checking it against the 16 KB buffer length. By modifying loopback handshake traffic with NFQUEUE, an attacker could turn a constrained write into a 16-byte zero write at a selected 16 KB-aligned offset. XBOW used that primitive to overwrite identity fields in a sprayed Linux cred structure, zeroing euid and obtaining a root shell without an information leak or a second vulnerability. The exploit depended on heap grooming, buffer-token reuse, and stopping after the first successful escalation to avoid corrupting structures needed for later connections. On Ubuntu 24.04 with Linux 7.1.0-rc6 and mitigations disabled, it succeeded on 22 of 100 boots, with the first success on boot seven. The report says XBOW handled threat modeling, auditing, discovery, validation, and exploit development, but researchers had to revive the MITM approach, correct its mistaken assumption that it had a write-what-where primitive, and direct it to use the zero write against cred rather than seek a stronger primitive. XBOW attributes these failures to cost-sensitive reasoning, persistent assumptions, and loss of earlier insights in long contexts. The team says it redesigned the system around multiple agents and now reports autonomous vulnerability discovery, patch production, reporting, and exploit development. The vulnerability was reported and patched on June 19, approved on July 7, and publicly assigned CVE-2026-72018 on August 17, 2026.