Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Aids Discovery of Linux Kernel Vulnerability Exploit

AI Aids Discovery of Linux Kernel Vulnerability Exploit

Posted on July 28, 2026 By CWS

In a significant breakthrough in cybersecurity, STAR Labs has revealed a Linux kernel flaw that allows a standard local user to gain root privileges on the targeted CentOS Stream 9. Tracked as CVE-2026-53264 with a CVSS score of 7.8, this vulnerability emerges from a use-after-free race in the kernel’s network traffic-control subsystem. Researcher Lee Jia Jie credited artificial intelligence (AI) for expediting the identification and development of the exploit. Although this is a local privilege escalation and not a remote code execution, it still requires an intruder to have initial access to the machine.

Exploit Development and Requirements

The exploit demands specific conditions, including unprivileged user namespaces and particular kernel configurations like CONFIG_NET_ACT_GACT and CONFIG_NET_CLS_FLOWER. Additionally, a kernel-specific return-oriented programming (ROP) chain with hardcoded offsets is necessary. Despite these constraints narrowing the vulnerability’s immediate impact, the complete exploit code is now publicly accessible, raising concerns for unpatched systems.

An upstream fix was introduced on June 1, 2026, and has been backported to various stable kernel branches. Vulnerable versions start from Linux 4.14, while fixed versions include 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, and 7.0.13. Users are advised to update to a distribution kernel with the fix, rather than depending solely on version numbers.

AI’s Role in Vulnerability Detection

In his technical documentation, Lee elaborated on AI’s role in detecting the vulnerability, crafting a Kernel Address Sanitizer (KASAN) proof of concept, and refining the race window. While AI facilitated these processes, Lee emphasized the necessity of human judgment throughout. STAR Labs has yet to disclose specific details regarding the AI system utilized, the testing circumstances, or the timeline for public disclosure.

The flaw is rooted in the handling of Linux traffic-control actions, where concurrent operations could result in one thread accessing an action object that another has already freed. The patch addresses this by postponing the free operation until all readers have completed their tasks.

Implications and Future Outlook

The exploit manipulates user and network namespaces to acquire namespace-local CAP_NET_ADMIN without host administrator rights. It exploits a clsact qdisc and flower filter to access the vulnerable path, utilizing timerfd and epoll operations to extend the race window and reclaim the freed object. The ROP chain subsequently alters core_pattern.

In trials conducted by Lee, the exploit was consistently effective, though its reliance on fixed gadget offsets necessitates rebuilding for other kernel versions, potentially limiting its adaptability. While the immediate threat may be limited, the release of public exploit code highlights the urgency for systems to apply patches.

The vulnerability’s discovery credits Kyle Zeng, also known as KyleBot, who reportedly identified the flaw independently before it was disclosed at the TyphoonPwn 2026 competition. As of late July 2026, distribution status remains varied, with some systems still marked as vulnerable. The public availability of the exploit underscores the need for expedient action to mitigate potential risks.

The Hacker News Tags:AI, CentOS Stream 9, CVE-2026-53264, Cybersecurity, kernel exploit, kernel patch, Linux, Linux security, network traffic-control, privilege escalation, ROP chain, security patch, STAR Labs, vulnerability discovery

Post navigation

Previous Post: Microsoft Teams Vishing Attack Exploits Quick Assist
Next Post: Act Security Launches to Tackle AI-Induced Patch Challenges

Related Posts

Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More The Hacker News
Fraudulent Android Apps Stole Millions via Fake Subscriptions Fraudulent Android Apps Stole Millions via Fake Subscriptions The Hacker News
A Look Inside Pillar’s AI Security Platform A Look Inside Pillar’s AI Security Platform The Hacker News
Malicious Outlook Add-In Exploits Supply Chain Flaws Malicious Outlook Add-In Exploits Supply Chain Flaws The Hacker News
A Pragmatic Approach To NHI Inventories  A Pragmatic Approach To NHI Inventories  The Hacker News
Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Finds Linux Kernel Vulnerability Enabling Root Access
  • Act Security Launches to Tackle AI-Induced Patch Challenges
  • AI Aids Discovery of Linux Kernel Vulnerability Exploit
  • Microsoft Teams Vishing Attack Exploits Quick Assist
  • Critical TeamCity Vulnerability Demands Immediate Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Finds Linux Kernel Vulnerability Enabling Root Access
  • Act Security Launches to Tackle AI-Induced Patch Challenges
  • AI Aids Discovery of Linux Kernel Vulnerability Exploit
  • Microsoft Teams Vishing Attack Exploits Quick Assist
  • Critical TeamCity Vulnerability Demands Immediate Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark