« All posts

AI Agent XBOW Finds and Exploits a Linux Kernel Bug (CVE-2026-72018)

XBOW's AI security agent found and exploited a Linux kernel bug (CVE-2026-72018) via SMC-D, achieving full root privilege escalation.

XBOW, an AI-driven security research system, discovered and exploited CVE-2026-72018, an out-of-bounds write in the Linux kernel's SMC-D networking code that human auditors had dismissed as too weak to be worth pursuing. Reachable by any unprivileged user with CAP_NET_ADMIN, the bug let XBOW build a full local privilege escalation chain to root using nothing but a single 16-byte, partially-controlled write.

The root cause traces to a recent refactor: the DIBS abstraction and its dibs_loopback driver made SMC-D — previously mainframe-only IBM Z code — runnable on ordinary x86 Linux over loopback, with no special hardware required. Bounds checks that protected the original hardware-mediated buffer paths were never re-validated against a malicious, peer-controlled dmbe_idx and token, letting attacker-supplied offset arithmetic reach an unchecked memory copy deep in the transmit path.

For engineers, the finding is less about one bug and more about triage economics: a primitive too constrained for a human researcher to justify weeks of effort was exactly the kind of long-running, adversarial, protocol-aware work an AI agent could pursue to completion. XBOW handled the bulk of threat modeling, auditing, and exploit development autonomously, though a few pivotal moments still required human judgment — a signal for how autonomous vulnerability research systems need to be designed going forward.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work