CVE-2026-72018

LOWCVSS 7.8 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset and size in move_data() The loopback move_data() performs a memcpy into the registered DMB without checking whether offset + size exceeds the DMB length. Unlike real ISM hardware, which enforces memory region bounds natively, the software loopback has no such protection. A peer-supplied out-of-bounds offset or oversized write would result in an OOB write past the allocated kernel buffer. Add an explicit bounds check before the memcpy to reject such requests with -EINVAL.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 6 mentions on most recent observed day (2026-09-30)
  • 8 total mentions across 2 days

Deep dive

Activity timeline8 mentions / 2d
02356Mentions · 2026-09-29: 2Mentions · 2026-09-30: 609-2909-30
Referenced assets5 URLs
Full discourse8 posts
  • XBOW@Xbow

    Can agents find and exploit a Linux kernel bug? Where does autonomy break down? XBOW uncovered what human researchers had largely missed: a vulnerability buried deep in the Linux kernel—and took it all the way to a working LPE exploit. CVE-2026-72018: an out-of-bounds write vulnerability in the Linux kernel that can be triggered by an unprivileged user with administrative network capabilities (CAP_NET_ADMIN), providing a primitive that can be leveraged for local privilege escalation to root. 🧵 1/ The exploit reaching a shell as root (uid=0).

    6124713412.0K
    13.3K followersView on X
  • Cyber Security News@The_Cyber_News

    AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access Details: https://cybersecuritynews.com/ai-agent-finds-linux-kernel-bug/ CVE-2026-72018 is a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access. The flaw affects the DIBS loopback implementation used by the SMC-D shared-memory communication path; a missing bounds check lets attacker-controlled data be copied beyond an allocated kernel buffer. The issue exists in the dibs_loopback driver, which enables Shared Memory Communications Direct, or SMC-D, on standard x86 Linux systems without IBM Z hardware. #cybersecuritynews

    21101872.1K
    74.7K followersView on X
  • XBOW@Xbow

    Read more in the full technical write up here: https://xbow.com/blog/no-time-to-pwn-cve-2026-72018 https://t.co/8XUs2iZZtX

    03063919
    13.3K followersView on X
  • Nicolas Krassas@Dinosn

    No Time to Pwn – Can AI Find and Exploit the Linux Kernel? https://xbow.com/blog/no-time-to-pwn-cve-2026-72018

    010431.8K
    161.8K followersView on X
  • /r/netsec@_r_netsec

    No Time to Pwn – Can AI Find and Exploit the Linux Kernel? https://xbow.com/blog/no-time-to-pwn-cve-2026-72018

    02011537
    34.1K followersView on X
  • ExploitGrid@exploitgrid

    A 16-byte zero write became root. XBOW developed a working LPE for CVE-2026-72018, a Linux kernel OOB write in the DIBS loopback driver. CVSS 7.8 | EPSS 0.16% ExploitGrid: 31.3/100 No known public exploit 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-72018

    0101044
    222 followersView on X
  • The Daily Tech Feed@dailytechonx

    Big security alert: AI agent discovered a Linux kernel bug (CVE-2026-72018) in the dibs_loopback SMC-D driver that converts a narrowly constrained memory write into full root access. Despite only permitting a fixed 16-byte zero write, the exploit zeros credential fields—triggering privilege escalation—without needing arbitrary write or info leaks. The attack requires CAP_NET_ADMIN, loopback networking, and a vulnerable kernel. Update systems, enforce minimal privileges, and patch now. #KernelSecurity #Linux #AI #Vulnerability #RootAccess #SMCD https://thedailytechfeed.com/ai-agent-uncovers-linux-kernel-vulnerability-allowing-root-access/

    0000022
    754 followersView on X
  • Undercode News@undercode_news

    🚨 #Linux Kernel Flaw #CVE-2026-72018 Enables Root Access Through a Constrained Memory Corruption -Fact Checker: ✅: 3 ❌: 1 || 3/4 → Score: 75% 🦾 -Prediction: 📈 1 Positive | 📉 1 Negative https://undercodenews.com/linux-kernel-flaw-cve-2026-72018-enables-root-access-through-a-constrained-memory-corruption/

    0000023
    129 followersView on X

Explore more