Rewterz

Apple CoreGraphics Zero-Day Actively Exploited

September 29, 2026
Rewterz

UAT-11587 Conducts China-Nexus Cyber Espionage Campaign Across Asia – Active IOCs

October 1, 2026

AI Agent Discovers Linux Kernel Flaw Enabling Root Access

Severity

High

Analysis Summary

Researcher has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability affecting the DIBS loopback implementation used by the SMC-D shared-memory communication path. The flaw is caused by a missing bounds check in the dibs_loopback driver, allowing attacker-controlled data to be copied beyond an allocated kernel buffer. SMC-D was historically associated with IBM mainframe environments and internal shared-memory devices, but the introduction of the dibs_loopback virtual device made the functionality accessible on standard x86 Linux systems without IBM Z hardware, expanding its exposure to a local attack surface.

Researcher identified that a peer-controlled dmbe_idx value could influence offset calculations during SMC connection setup, eventually reaching the move_data() routine, where memcpy() performed the unsafe copy without validating the destination boundaries. The demonstrated attack requires CAP_NET_ADMIN, which was used to enable SMC-D and manipulate loopback CLC handshake traffic through an NFQUEUE-based interception setup. Although the resulting exploit primitive was highly restricted providing only a 16-byte zero write at a partly controlled kernel-memory location the researchers demonstrated that it could still be security-critical because the write could target the Linux kernel's cred structure.

The exploit targeted security-sensitive fields within the kernel cred structure, specifically the effective user ID (euid). By placing the 16 zero bytes over the relevant fields, the exploit could change the effective UID to zero, which Linux treats as root, allowing the affected process to establish a root identity and spawn a root shell. XBOW reported successful privilege escalation on 22 of 100 boots, with the first successful attempt occurring on the seventh boot. Testing was performed on Ubuntu 24.04 with Linux 7.1.0-rc6 and kernel mitigations disabled, meaning exploitation reliability may vary depending on the Linux distribution, kernel build, memory allocator behavior, and enabled mitigations. The CVE has a CVSS 3.1 score of (High), with local attack vector, low privileges required, no user interaction, and high impacts to confidentiality, integrity, and availability.

The vulnerability also highlights both the capabilities and limitations of autonomous vulnerability research. Researcher's AI agent performed threat modeling, code auditing, vulnerability discovery, validation, and much of the exploit-development process, demonstrating its ability to analyze and test obscure kernel subsystems extensively. However, human researchers were still required to redirect the agent toward local privilege escalation, revisit packet interception after an initially discarded approach, experimentally validate the restricted zero-write primitive, and focus on exploiting the available primitive rather than pursuing a more complex arbitrary-write or use-after-free chain. Organizations should apply Linux kernel updates containing the DIBS loopback bounds-check fix and reboot affected systems. Administrators should also review systems, workloads, and containers granted CAP_NET_ADMIN, as this capability is central to the demonstrated local exploitation path.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-72018

Remediation

  • Apply the latest Linux kernel security updates containing the fix for CVE-2026-72018 and reboot affected systems.
  • Ensure the DIBS loopback bounds-check fix is included in the deployed kernel version.
  • Review systems running the dibs_loopback driver and assess whether SMC-D functionality is required.
  • Restrict or remove CAP_NET_ADMIN from workloads and containers where it is not required.
  • Review containers and workloads with CAP_NET_ADMIN for potential local privilege-escalation exposure.
  • Monitor systems for suspicious activity involving SMC-D, loopback networking, and kernel-level privilege escalation.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.