Gaining ROOT privileges to the attacker on Linux allows them to gain control!
This vulnerability in the Linux kernel allows an attacker to gain ROOT privileges!
The vulnerability CVE-2026-72018 in the Linux kernel can allow an attacker to escalate the existing privileges on the system to root level. Researchers have determined that a 16-byte memory write is sufficient to exploit this vulnerability.
The Linux kernel is one of the most important parts of an operating system, managing interactions with applications, devices, memory, and other system resources. Therefore, vulnerabilities in the kernel can have a serious impact on system security.
Recently, a vulnerability with the identifier CVE-2026-72018 was discovered in the dibs_loopback component within the SMC-D mechanism of the Linux kernel. This issue can cause data to be written to memory to extend beyond its allocated boundary.
The vulnerability was rated 7.8 on the CVSS 3.1 scale and has a high risk level.
What is the vulnerability?
Simply put, it requires checking where and how much data a program is writing to memory.
For example, if a program has 100 bytes allocated in memory, it should not write data outside of this area.
In the case of CVE-2026-72018, this check was not performed sufficiently in the dibs_loopback component of the Linux kernel.
As a result, an attacker can be forced to write data outside the allocated memory area when certain conditions are met.
This is known as Out-of-Bounds Write, meaning writing beyond the memory boundary.
This can lead to the corruption of other important data in kernel memory.
What is SMC-D and how did the problem occur?
SMC-D is one of the mechanisms used for data exchange in Linux systems.
It was initially used primarily in specialized server and mainframe environments like IBM Z. Therefore, some parts of this mechanism were not widely used on standard x86 computers.
Later, the dibs_loopback virtual device was added to the Linux kernel. This allowed its use in standard Linux systems even without special hardware devices for SMC-D functions.
As a result, a previously less-used code part became usable in standard Linux systems as well.
The problem related to checking memory boundaries in this component was identified.
The most interesting aspect is that just a 16-byte write might be sufficient.
The vulnerability is distinguished from many other memory corruption vulnerabilities.
Generally, when an attacker gains the ability to write to memory, they try to use it as much as possible—that is, to write the necessary data to the necessary address.
In the case of CVE-2026-72018, the opportunity was very limited.
XBOW researchers found that an attacker can write 16-byte zero values to a specific memory area.
At first glance, this seems like a very small possibility.
However, some data in the Linux kernel performs very important tasks. Therefore, even a small amount of memory writing, if it lands in the right place, can lead to serious consequences.
How can 16 bytes lead to ROOT privileges?
In a Linux system, there is information that defines the user and group privileges for every process.
There is also a credential structure used to determine which privileges a process has.
In the Linux system, UID 0 represents the root user.
Researchers have shown that by exploiting limited memory writes, it is possible to affect values important for credential structures.
As a result, the user identifier of a process can be changed to a value related to root.
That is, the attack is described as follows:
Vulnerability in the Linux kernel → Out-of-Bounds Write from memory → Modification of important privilege data → Process with ROOT privileges
This is considered a security issue that leads to the escalation of local privileges, rather than just a simple memory corruption.
Can an attacker exploit this?
No.
To exploit this vulnerability, the attacker must have a certain level of privilege on the system.
Specifically, the CAP_NET_ADMIN capability is required.
CAP_NET_ADMIN is one of the special privileges that allows performing certain network-related management operations in a Linux system.
This aspect is particularly important for servers and containers.
If a malicious or compromised process has the CAP_NET_ADMIN permission, it may have a closer opportunity to exploit this vulnerability.
Therefore, organizations must check who and why this capability has been granted.
Artificial intelligence identified the vulnerability
Another noteworthy aspect of the CVE-2026-72018 incident is that an autonomous cybersecurity platform named XBOW was used in investigating it.
This platform automated a large part of the process of analyzing, identifying, verifying, and exploiting vulnerabilities in the Linux kernel code.
This shows that the opportunities for artificial intelligence and autonomous agents in cybersecurity are constantly expanding.
However, the role of human experts in the investigation process remains.
Experts guided the agent in the desired direction, reviewed some attack scenarios, and demanded practical experiments with the identified memory writes.
Therefore, the conclusion that artificial intelligence has completely replaced the role of human experts is not supported. On the contrary, it shows that AI is being used as an additional tool to accelerate complex technical investigations and analyze large amounts of code.
How easy is it to exploit the vulnerability?
In the experience conducted by researchers, every attempt to exploit the vulnerability was unsuccessful.
According to XBOW data, out of 100 attempts, privileges were escalated in only 22.
However, this result cannot be considered the same for all Linux systems.
Because the exploit effectiveness can be affected by:
- The version of the Linux kernel;
- The operating system distribution;
- Kernel configuration;
- Memory management mechanisms;
- Security protections;
- Other system settings.
Furthermore, researchers conducted the experiment in certain conditions and in environments where some kernel protection mechanisms were disabled.
Therefore, concluding that the 22/100 ratio is replicated in real systems is incorrect.
What should organizations do?
1. Update the Linux kernel
Install the security updates released for CVE-2026-72018.
Particular attention should be paid to Linux servers, important information systems, and Linux servers running large-scale services connected to the internet.
2. Check the CAP_NET_ADMIN privilege
Determine which services have the CAP_NET_ADMIN privilege on servers and containers.
If this privilege is not necessary for the service to function, it should be removed.
3. Monitor Containers
Regularly check the Linux capabilities granted to containers.
It is recommended to use broad-ranging privileges like CAP_NET_ADMIN only when necessary.
4. Monitor Kernel Security Updates Regularly
Do not wait for the release of the new Linux kernel version; install security updates provided by the operating system distribution regularly.
5. Check Suspicious Root Processes
If a service or process that normally does not have root privileges starts running with higher privileges on the system unexpectedly, this situation should be investigated.
Furthermore, it is recommended to analyze whether there are attempts to escalate privileges through system logs and security monitoring tools.
The vulnerability in the Linux kernel's SMC-D mechanism in the dibs_loopback component is a highly critical vulnerability.
The problem arises because the boundaries of memory were not sufficiently checked before writing data to memory. In some circumstances, exploiting this vulnerability can allow an attacker to modify important data in kernel memory and consequently escalate their privileges to root level.
One of the most important aspects of the vulnerability is that even a limited memory write might be sufficient. This demonstrates that even a small apparent memory error in the Linux kernel can have a serious impact on system security.
Furthermore, this investigation shows that artificial intelligence-based autonomous security tools are increasingly being used to detect and analyze vulnerabilities in complex software in cybersecurity.
Organizations are advised to update the Linux kernel with relevant security updates, check the use of CAP_NET_ADMIN privilege, and separately monitor servers and containers that have this privilege.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.