Vulnerability
Published 2026-08-15
Verified 2026-09-30

Linux CVE-2026-72018 (CVSS 7.8): DIBS loopback OOB write → LPE with CAP_NET_ADMIN; XBOW demonstrates root LPE (28 Sep)

Linux kernel CVE-2026-72018 (published 15 August 2026; XBOW research write-up 28 September 2026) is an out-of-bounds write in dibs_loopback move_data(): the software SMC-D loopback path memcpy'd into a registered DMB without checking offset+size against DMB length. A local user with CAP_NET_ADMIN can stage a malicious SMC-D peer over loopback, drive a constrained zero-write past the buffer, and escalate to root (XBOW demonstrated reliable LPE). CNA CVSS 3.1 7.8 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Affected from the 6.10-era DIBS loopback introduction; fixed in stable trains including 6.12.97, 6.18.40, 7.1.5 and 7.2 (per CVE.report / Linux CNA). Primary: CVE.report / kernel stable commits; wire: XBOW 28 Sep + Talkback.

Product
Linux kernel (SMC-D / DIBS loopback — drivers/dibs/dibs_loopback.c)
Versions
Affected: Linux kernels with DIBS loopback from 6.10 introduction until fixed. Unaffected per Linux CNA: 6.12.97 (6.12.*), 6.18.40 (6.18.*), 7.1.5 (7.1.*), 7.2 and later. Distro backports vary — check package changelog for CVE-2026-72018.
CVSS
(CVSS 3.1 HIGH, Linux CNA)
Exploited in Australia?
unknown
Patch to
Install a kernel at or above 6.12.97 / 6.18.40 / 7.1.5 / 7.2 (or distro package that cites CVE-2026-72018). Prioritise hosts where untrusted users or containers can obtain CAP_NET_ADMIN. Until patched, restrict CAP_NET_ADMIN and SMC/DIBS loopback exposure.

Primary: CVE.report — CVE-2026-72018 dibs loopback move_data bounds check (15 Aug 2026) · Vendor: Linux kernel stable — dibs loopback fix commit · CVE: CVE-2026-72018 · XBOW — No Time to Pwn: CVE-2026-72018 LPE research (28 Sep 2026)

vulnerabilities cloud