In a technical account published Sept. 28, security company XBOW said its AI-assisted research identified and exploited CVE-2026-72018, an out-of-bounds write in the Linux kernel’s DIBS loopback path. The local privilege-escalation setup XBOW described required CAP_NET_ADMIN, a Linux capability for network administration.
What CVE-2026-72018 does in the Linux kernel
The flaw is in move_data(), part of the DIBS software loopback driver. The operation copied data into a registered buffer without checking that the offset plus the size would stay within that buffer’s length. That missing bounds check allowed a write beyond the buffer.
The CVE record assigns the vulnerability a CVSS 3.1 score of 7.8 (High).
XBOW’s reported exploit test
XBOW says its local exploit setup needed CAP_NET_ADMIN to register a UEID and install the NFQUEUE rule used in the test. A process without that capability could not carry out the setup XBOW described.
In its test, XBOW reported successful local privilege escalation in 22 of 100 separate boots. The test ran Ubuntu 24.04 with Linux 7.1.0-rc6 on x86_64, with all kernel mitigations disabled; the first success came on boot seven. Those results describe that specific configuration.
What a shared kernel means for containers
Containers share the host’s Linux kernel, so a kernel flaw can affect the boundary between a container and its host. For this CVE, the exploit path XBOW described required CAP_NET_ADMIN; that prerequisite matters when assessing which processes can reach the reported setup.
Version entries in the CVE record
The CVE record lists Linux 6.10 as affected. It lists versions before 6.10 as unaffected, along with 6.12.97 and later in the 6.12 series, 6.18.40 and later in the 6.18 series, 7.1.5 and later in the 7.1 series, and 7.2.
Amazon Linux’s advisory marks Amazon Linux 2 Core and its listed 5.4, 5.10, and 5.15 extra kernels as not affected. It also marks the listed Amazon Linux 2023 kernel, kernel6.12, and kernel6.18 packages as not affected.