A high-severity Linux kernel vulnerability, tracked as CVE-2026-72018, lets a local attacker with CAP_NET_ADMIN privileges escalate to root.
This exploitation involves an out-of-bounds write in the Shared Memory Communications Direct (SMC-D) DIBS loopback implementation.
Researchers at XBOW discovered and demonstrated the flaw, creating a local privilege escalation proof of concept using a constrained 16-byte zero-write primitive.
Linux Kernel CVE-2026-72018 Flaw
The vulnerability is located in the `dibs_loopback` driver’s `move_data()` routine. This affected function performs a `memcpy()` operation into a registered Direct Memory Buffer (DMB). Still, it does not ensure that the provided offset and write size are within the limits of the allocated buffer.
While the Shared Memory hardware enforces memory region boundaries, the software-backed DIBS loopback implementation does not implement equivalent validation.
Consequently, a malicious peer can provide either an out-of-range offset or an oversized write, leading the kernel to write beyond the target DMB allocation and corrupt adjacent memory.
The upstream fix introduces validation that rejects requests when the offset plus size exceeds the DMB length, returning -EINVAL instead of attempting the data copy.
This issue is classified as CWE-787, which indicates an out-of-bounds write weakness. Red Hat has warned that successful exploitation can lead to memory corruption, denial-of-service conditions, or even arbitrary code execution, depending on the affected objects and memory layout.
SMC is an IBM-designed networking technology that reduces data copying and protocol-processing overhead by moving application traffic to shared-memory or RDMA-backed transports while retaining the socket interface. Its SMC-D variant allows systems on the same host to communicate through shared memory.
Historically, SMC-D was primarily associated with specialized IBM Z and ISM hardware. However, the introduction of the `dibs_loopback` virtual transport made relevant SMC-D pathways accessible on standard x86 Linux hosts without dedicated hardware. This design change turned code previously considered difficult to access into a practical local attack surface.
XBOW’s analysis revealed that values carried in the SMC Connection Layer Control handshake could influence the transmit offset used by the DIBS layer.
Specifically, attacker-controlled fields such as `dmbe_idx` and `dmbe_size` affect the offset calculation, while the DMB token identifies the destination buffer. The unchecked offset ultimately reaches the vulnerable `memcpy()` operation in the loopback driver.
The demonstrated exploit did not employ a conventional arbitrary write. Researchers reported that the practical primitive produced a highly limited write: 16 zero bytes at a partially controllable, 16 KB-aligned offset across a multi-megabyte range.
To exploit the flaw locally, researchers intercepted loopback CLC traffic using an `nftables NFQUEUE` rule, modified handshake fields, recomputed packet checksums, and reinjected the altered packets. This scenario requires CAP_NET_ADMIN privileges for the necessary SMC-D setup and for packet interception and modification.
The exploit relied on heap grooming to position a Linux kernel `cred` object immediately after the vulnerable buffer. By aligning the zero-write with credential identity fields such as `suid`, `sgid`, `euid`, and `egid`, the attack could effectively zero a target process’s effective UID. Once the effective UID turned to zero, the affected process was treated as root, allowing it to establish a root shell.
XBOW tested their proof of concept on Ubuntu 24.04 running Linux 7.1.0-rc6 with kernel mitigations disabled. Of 100 separate boots, root privileges were gained in 22 instances, with the first successful escalation occurring on the seventh boot.
Although this reliability rate should not be interpreted as a universal success rate for real-world exploits, it confirms that the constrained primitive can lead to privilege escalation under favorable heap conditions.
Administrators are urged to install kernel updates from their distributions that include the respective fix. The NVD record lists kernel versions 6.12.97, 6.18.40, and 7.1.5 or later as unaffected. Still, organizations should rely on their vendor’s advisory and package status rather than making assumptions based solely on kernel versions.
This case highlights a broader risk for kernel maintainers: virtual transports and hardware-independent compatibility layers can transform previously niche code into a widely accessible attack surface.
Security reviews should re-evaluate such ports using an explicit malicious-peer model, especially where protocol-controlled fields feed into offset calculations or low-level memory-copy operations.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC





