Back to News
Cybersecurity

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

Cyber RTJuly 28, 20263 min read
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs disclosed a Linux kernel exploit (CVE-2026-53264) that elevates local user privileges to root on CentOS Stream 9. The flaw, a use-after-free race in the network traffic-control subsystem, was discovered with AI assistance. The exploit requires specific kernel options and user namespaces, limiting exposure. An upstream fix was released on June 1, 2026. Public exploit code heightens urgency for patching vulnerable systems.

STAR Labs has released a Linux kernel exploit that allows a local user to gain root access on the CentOS Stream 9 build. The vulnerability, identified as CVE-2026-53264, is a use-after-free race condition in the kernel's network traffic-control subsystem. With a CVSS score of 7.8, this flaw represents a significant security risk, although it requires an attacker to have an initial foothold on the machine, as it is a local privilege escalation rather than a remote code execution vulnerability. Researcher Lee Jia Jie utilized artificial intelligence (AI) to identify the bug and expedite the development of the exploit. The exploit necessitates specific conditions, including unprivileged user namespaces and certain kernel options, which limit its immediate applicability. However, the full exploit source code has been made publicly available, increasing the urgency for systems to be patched. The upstream fix for this vulnerability was implemented on June 1, 2026, and has been backported to several stable kernel branches. Vulnerable versions begin with Linux 4.14, and fixed releases include versions 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, and 7.0.13. Users are advised to install a distribution kernel carrying the fix rather than relying solely on the upstream version number. Despite the public availability of the exploit code, there have been no reports of the vulnerability being exploited in the wild as of late July 2026. The Hacker News noted that the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Lee's technical write-up highlighted the role of AI in discovering the vulnerability and optimizing the exploit, although human judgment was crucial throughout the process. The vulnerability arises from improper lifecycle handling of Linux traffic-control actions, where concurrent operations can lead to use-after-free conditions. The exploit manipulates user and network namespaces to gain CAP_NET_ADMIN privileges locally, exploiting the race condition through specific kernel operations and a return-oriented programming (ROP) chain. The exploit strategy involves placing a copy of itself in a memory file descriptor (memfd) and crashing a child process, which triggers the memfd-backed binary as the root core-dump handler. Lee reported a high success rate in his tests, though the exploit's reliability and adaptability to other kernel packages remain unverified by independent sources. The public release of the exploit code has heightened the need for systems to be patched, particularly those with the necessary conditions for the exploit to succeed. Distribution status varies, with some Linux distributions having already released fixed kernels, while others still list the vulnerability as pending. The AI-assisted process in identifying and exploiting the bug demonstrates the evolving role of AI in cybersecurity research.