Threat reportVulnerabilityTL-2026-1744

CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege Escalation

highACTIVE

CVE-2026-53264 (TL-2026-1744) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-07-28 and last reviewed 2026-08-02. It has no confirmed attribution, affects Linux Linux Kernel (net/sched), references 2 CVEs (CVE-2026-53264, CVE-2026-64300), maps to 16 MITRE ATT&CK techniques (T1005, T1027.011, T1059.004), and is covered by 9 detection rules and 39 indicators of compromise.

CVSS
7.8/10High
CVEs
2Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
39Indicators of compromise

Key facts for TL-2026-1744

Threat ID
TL-2026-1744
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
39
Updates
2026-08-02 · revalidated 1× · latest source

Malware and tooling in CVE-2026-53264

Malware and tooling: KyleBot, STAR Labs CVE-2026-53264 PoC (poc.c / pwn_utils.cpp)

How CVE-2026-53264 works

A use-after-free race condition in the Linux kernel's net/sched traffic-control subsystem (CVE-2026-53264) lets a local unprivileged user with unprivileged user namespaces escalate to root; STAR Labs researcher Lee Jia Jie used AI assistance to find the bug, generate a KASAN crash proof, and cut the exploitation race window from 15+ minutes to single-digit seconds, while an AI system (KyleBot, operated by Kyle Zeng) independently reported the same bug two days earlier. A public PoC is on GitHub; upstream patched June 1, 2026, but Ubuntu and SUSE remain unpatched as of publication. A related use-after-free in the perf events subsystem (CVE-2026-64300) was surfaced by the same research effort.

CVE-2026-53264 is a use-after-free (CWE-416, CVSS 3.1 7.8: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) in the Linux kernel's net/sched packet-scheduling subsystem, rooted in tcf_idr_check_alloc() (net/sched/act_api.c, include/net/act_api.h). A race between concurrent RTM_NEWTFILTER and RTM_DELTFILTER netlink operations lets one code path call kfree() on a traffic-control action immediately after removing it from the IDR radix tree, without waiting for the RCU grace period to complete, while another CPU still holds and dereferences the now-stale pointer under RCU read-side protection. Critically, the legitimate action-management routes RTM_NEWACTION/RTM_DELACTION are gated behind CAP_NET_ADMIN, but the vulnerable filter-management routes RTM_NEWTFILTER/RTM_DELTFILTER reach the same underlying action lifecycle code without that same restriction being effective inside a namespace — which is what makes the bug reachable from an unprivileged context in the first place. The upstream fix (commit 5057e1aca011e51ef51498c940ef96f3d3e8a305, landed 2026-06-01) defers the free via call_rcu(). The bug affects Linux 4.14 through 7.1-rc6 (present in the kernel for roughly 2-3 years before discovery per derivative reporting) and is fixed in 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, and mainline 7.1-rc7.

Exploitation requires unprivileged user namespaces plus CONFIG_NET_ACT_GACT and CONFIG_NET_CLS_FLOWER kernel options. STAR Labs' demonstrated exploit chain: (1) call clone()/unshare() with the CLONE_NEWUSER flag to create an unprivileged user namespace (paired with a network namespace), which grants namespace-local CAP_NET_ADMIN without host administrator rights; (2) set up a clsact qdisc with a flower filter and gact action, then race RTM_NEWTFILTER/RTM_DELTFILTER netlink messages — using timerfd and epoll to widen the race window — to trigger the UAF in tcf_idr_check_alloc(); (3) leak a kernel address via dmesg/MSR parsing (dmesg_msr_kaslr.c) to defeat KASLR; (4) groom/reclaim the freed slot using KEYCTL_UPDATE keyring syscalls with attacker-controlled data; (5) build a ROP chain with hardcoded offsets to overwrite /proc/sys/kernel/core_pattern; (6) write a copy of the payload binary into an anonymous, disk-less file via memfd_create() and deliberately crash a child process, causing the kernel's core-dump handler to execute the memfd-backed binary as root — a fileless/reflective code-loading pattern (the Linux memfd_create() fileless-execution chain is a documented example under MITRE ATT&CK T1620 Reflective Code Loading). On a CentOS Stream 9 laptop the exploit succeeded 10/10 runs in roughly 9-111 seconds (with some runs under 10 seconds), versus a 15+ minute baseline before AI-assisted race-window optimization.

Researcher Lee Jia Jie (STAR Labs, Singapore) — in his first Linux kernel research effort, done during an internship — stated AI assisted with vulnerability discovery, KASAN proof-of-concept generation, and race-condition timing optimization, while cautioning that "AI still has many blind spots and lapses in reasoning ability" and that manual analysis remained essential for exploitation logic and real-world validation. Separately, Kyle Zeng (handle KyleBot) used an AI-assisted research system to independently discover and report the same CVE-2026-53264 bug roughly two days ahead of Lee, shortly before the TyphoonPwn 2026 competition (TyphoonCon, Seoul, 2026-05-25 through 2026-05-29); Zeng is credited as reporter in the upstream patch. Lee's STAR Labs submission placed 8th of 11 entrants in TyphoonPwn 2026's Linux Privilege Escalation category (prize pool up to $70,000), which closed after three winners were awarded. The original technical write-up underlying much of the derivative press coverage was published on Slippy Blog.

The same AI-assisted research pipeline also surfaced CVE-2026-64300, an unrelated use-after-free in the kernel's perf events subsystem (kernel/events/core.c): two perf events made to share a ring buffer via the PERF_EVENT_IOC_SET_OUTPUT ioctl can race during mmap, and map_range() reads auxiliary ring-buffer fields under only per-event locking instead of the required ring-buffer-level synchronization, so a page can be freed while still mapped. CVE-2026-64300 affects Linux 6.14 and later, is fixed in 6.18.39, 7.1.4, and 7.2-rc3, and was reported to disproportionately affect Intel bare-metal systems on RHEL-based and Arch desktop distributions (not Debian-based systems).

A public PoC for CVE-2026-53264 (Makefile, dmesg_msr_kaslr.c/.h, poc.c, pwn_utils.cpp/.h) is published at github.com/star-sg/CVE. As of 2026-07-28, Debian lists fixed kernels for its supported stable releases, but Ubuntu still marks multiple maintained kernel packages vulnerable and SUSE lists the issue as pending across multiple products — notably, SUSE's own severity assessment diverges from NVD's, rating the bug CVSS 5.5 versus NVD's 7.8. Neither CVE-2026-53264 nor CVE-2026-64300 appears in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

MITRE ATT&CK techniques used in TL-2026-1744

Collection

T1005 Data from Local System

Defense Evasion

T1027.011 Fileless Storage; T1211 Exploitation for Stealth; T1620 Reflective Code Loading

Execution

T1059.004 Unix Shell; T1106 Native API

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1546 Event Triggered Execution; T1611 Escape to Host

Discovery

T1082 System Information Discovery

Resource Development

T1587.004 Exploits; T1588.002 Tool; T1588.005 Exploits; T1588.006 Vulnerabilities; T1588.007 Artificial Intelligence; T1608.002 Stage Capabilities: Upload Tool

Affected products and versions in CVE-2026-53264

  • Linux — Linux Kernel (net/sched)
    Vulnerable versions: 4.14–5.10.258; 5.11–5.15.209; 5.16–6.1.175; 6.2–6.6.142; 6.7–6.12.93; 6.13–6.18.35; 6.19–7.0.12; 7.1-rc1–7.1-rc6
    Fixed in: 5.10.259; 5.15.210; 6.1.176; 6.6.143; 6.12.94; 6.18.36; 7.0.13; 7.1-rc7
  • Linux — Linux Kernel (perf events)
    Vulnerable versions: 6.14 through pre-6.18.39; 7.0–7.1.3; 7.2-rc1–7.2-rc2
    Fixed in: 6.18.39; 7.1.4; 7.2-rc3
  • Canonical — Ubuntu
    Vulnerable versions: multiple maintained kernel packages, as of 2026-07-28
  • SUSE — SUSE Linux
    Vulnerable versions: pending across multiple products, as of 2026-07-28
  • Debian — Debian
    Fixed in: supported stable releases, as of 2026-07-28
  • Red Hat — CentOS Stream 9
    Vulnerable versions: CentOS Stream 9 (STAR Labs exploit demonstration target)

Remediation for CVE-2026-53264

Patches

  • Upstream commit 5057e1aca011e51ef51498c940ef96f3d3e8a305 fixes CVE-2026-53264 by deferring action object freeing via call_rcu() until the RCU grace period completes
  • git.kernel.org stable commits 0cff05bd2186020f8706233e261016d149cc24db, 5948aaf64f81f217a25dcc2bf6c0779bca19566c, and c8b7e113f7b61eef2f017e6329c27c2331058c5a fix CVE-2026-64300

Immediate actions

  • Apply the upstream kernel patch (commit 5057e1aca011e51ef51498c940ef96f3d3e8a305) or upgrade to a fixed point release (5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, or 7.1-rc7+) to remediate CVE-2026-53264
  • Upgrade to kernel 6.18.39, 7.1.4, or 7.2-rc3 (or later) to remediate CVE-2026-64300
  • Restrict or disable unprivileged user namespace creation (kernel.unprivileged_userns_clone=0 or user.max_user_namespaces=0) on hosts that do not require it, removing the primary exploitation prerequisite (blocks the CLONE_NEWUSER path used to gain namespace-local CAP_NET_ADMIN)

Workarounds

  • Disable unprivileged user namespaces (sysctl kernel.unprivileged_userns_clone=0) to block the documented exploitation prerequisite for CVE-2026-53264
  • Restrict netlink NETLINK_ROUTE traffic-control filter/action management to CAP_NET_ADMIN-only contexts

Longer-term hardening

  • Track distro kernel patch rollout for CVE-2026-53264 — Debian has shipped fixed kernels, but Ubuntu and SUSE were still vulnerable/pending as of 2026-07-28 (note SUSE's own CVSS assessment of 5.5 diverges from NVD's 7.8) — and prioritize verification of backports
  • Restrict CONFIG_NET_ACT_GACT / CONFIG_NET_CLS_FLOWER exposure to unprivileged users on systems that do not need traffic-control filter management
  • Run KASAN/runtime UAF-detection builds in staging/CI to catch similar net/sched and perf-events races before they reach production kernels
  • Monitor for memfd_create()-backed anonymous execution and unexpected core_pattern modification/invocation as a detection surface for this exploit's fileless core-dump-handler abuse (MITRE T1620 / T1546)

CVEs associated with CVE-2026-53264

CVE-2026-53264, CVE-2026-64300

Weaknesses (CWE) in CVE-2026-53264

CWE-416

Timeline of CVE-2026-53264

  • Kyle Zeng, using his AI-assisted research system 'KyleBot', independently discovers and reports the net/sched use-after-free (CVE-2026-53264) roughly two days ahead of the TyphoonPwn 2026 competition (TyphoonCon, Seoul, 2026-05-25 through 2026-05-29); Zeng is credited as reporter in the upstream patch.
  • TyphoonPwn 2026 Linux LPE category registration closes at 1PM KST; random slot allocation announced 9AM KST, with STAR Labs researcher Lee Jia Jie drawing queue position 8 of 11.
  • TyphoonPwn 2026 hacking competition held at TyphoonCon (Seoul) against a fully patched CentOS Stream 9 Desktop target; Lee Jia Jie submits his exploit and whitepaper, but three earlier successful exploits close out the Linux LPE category before his demonstration turn.
  • Upstream Linux kernel fix for CVE-2026-53264 lands (commit 5057e1aca011e51ef51498c940ef96f3d3e8a305), deferring traffic-control action object freeing via call_rcu() until the RCU grace period completes.
  • SUSE opens Bugzilla #1269238 to track CVE-2026-53264 across SUSE Linux Enterprise Server, Desktop, Micro, and HA/HPC/Real-Time product lines.
  • CVE-2026-53264 published in NVD with CVSS 3.1 base score 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and CWE-416 (Use After Free) classification.
  • NVD record for CVE-2026-53264 last modified.
  • SUSE Bugzilla #1269238 last updated; SUSE scores the flaw CVSS 3.1 5.5 (availability-only impact), diverging from the 7.8 base score.
  • Related CVE-2026-64300 — a use-after-free in the kernel's perf events ring-buffer mapping (map_range()), triggered by racing two PERF_EVENT_IOC_SET_OUTPUT-linked events and surfaced by the same AI-assisted research effort — published in NVD.
  • CVE-2026-53264 and CVE-2026-64300 confirmed absent from the CISA Known Exploited Vulnerabilities catalog (1,655 entries as of the 2026-07-27 release) — no confirmed in-the-wild exploitation.
  • Infosecurity Magazine publishes the first mainstream-press report on Lee Jia Jie's AI-assisted discovery and exploitation of CVE-2026-53264.
  • Slippy Blog publishes the original technical write-up of STAR Labs researcher Lee Jia Jie's AI-assisted discovery and exploitation of CVE-2026-53264, subsequently republished/derived by multiple news outlets.
  • NVD record for CVE-2026-64300 last modified; fixes confirmed shipped in kernel 6.18.39, 7.1.4, and 7.2-rc3.
  • Red Hat Bugzilla #2507040 opened tracking the related CVE-2026-64300 perf/aux page use-after-free in map_range().
  • Additional outlets (Cryptika Cybersecurity, GuardianMSSP) republish and amplify coverage of the AI-assisted Linux kernel zero-day research.
  • The Hacker News publishes a detailed technical writeup of the exploit chain, confirms the public PoC repository at github.com/star-sg/CVE, and reports Ubuntu and SUSE still vulnerable (SUSE assessing the bug at a divergent CVSS 5.5) while Debian ships fixed kernels.
  • GovCERT.HK issues High Threat Security Alert A26-07-47 covering CVE-2026-53264.

Update history for TL-2026-1744

Sources cited for CVE-2026-53264

Detection coverage for TL-2026-1744

As of 2026-08-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1744 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
39 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats