# CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege Escalation

> A use-after-free race condition in the Linux kernel's net/sched traffic-control subsystem (CVE-2026-53264) lets a local unprivileged user with unprivileged user namespaces escalate to root; STAR Labs researcher Lee Jia Jie used AI assistance to find the bug, generate a KASAN crash proof, and cut the exploitation race window from 15+ minutes to single-digit seconds, while an AI system (KyleBot, operated by Kyle Zeng) independently reported the same bug two days earlier. A public PoC is on GitHub; upstream patched June 1, 2026, but Ubuntu and SUSE remain unpatched as of publication. A related use-after-free in the perf events subsystem (CVE-2026-64300) was surfaced by the same research effort.

- **Published:** 2026-07-28T00:00:00Z
- **Last reviewed:** 2026-08-02T07:14:56.050Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1744
- **ID:** TL-2026-1744
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 39 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-53264, CVE-2026-64300

## Description

CVE-2026-53264 is a use-after-free (CWE-416, CVSS 3.1 7.8: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) in the Linux kernel's net/sched packet-scheduling subsystem, rooted in tcf_idr_check_alloc() (net/sched/act_api.c, include/net/act_api.h). A race between concurrent RTM_NEWTFILTER and RTM_DELTFILTER netlink operations lets one code path call kfree() on a traffic-control action immediately after removing it from the IDR radix tree, without waiting for the RCU grace period to complete, while another CPU still holds and dereferences the now-stale pointer under RCU read-side protection. Critically, the legitimate action-management routes RTM_NEWACTION/RTM_DELACTION are gated behind CAP_NET_ADMIN, but the vulnerable filter-management routes RTM_NEWTFILTER/RTM_DELTFILTER reach the same underlying action lifecycle code without that same restriction being effective inside a namespace — which is what makes the bug reachable from an unprivileged context in the first place. The upstream fix (commit 5057e1aca011e51ef51498c940ef96f3d3e8a305, landed 2026-06-01) defers the free via call_rcu(). The bug affects Linux 4.14 through 7.1-rc6 (present in the kernel for roughly 2-3 years before discovery per derivative reporting) and is fixed in 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, and mainline 7.1-rc7.

Exploitation requires unprivileged user namespaces plus CONFIG_NET_ACT_GACT and CONFIG_NET_CLS_FLOWER kernel options. STAR Labs' demonstrated exploit chain: (1) call clone()/unshare() with the CLONE_NEWUSER flag to create an unprivileged user namespace (paired with a network namespace), which grants namespace-local CAP_NET_ADMIN without host administrator rights; (2) set up a clsact qdisc with a flower filter and gact action, then race RTM_NEWTFILTER/RTM_DELTFILTER netlink messages — using timerfd and epoll to widen the race window — to trigger the UAF in tcf_idr_check_alloc(); (3) leak a kernel address via dmesg/MSR parsing (dmesg_msr_kaslr.c) to defeat KASLR; (4) groom/reclaim the freed slot using KEYCTL_UPDATE keyring syscalls with attacker-controlled data; (5) build a ROP chain with hardcoded offsets to overwrite /proc/sys/kernel/core_pattern; (6) write a copy of the payload binary into an anonymous, disk-less file via memfd_create() and deliberately crash a child process, causing the kernel's core-dump handler to execute the memfd-backed binary as root — a fileless/reflective code-loading pattern (the Linux memfd_create() fileless-execution chain is a documented example under MITRE ATT&CK T1620 Reflective Code Loading). On a CentOS Stream 9 laptop the exploit succeeded 10/10 runs in roughly 9-111 seconds (with some runs under 10 seconds), versus a 15+ minute baseline before AI-assisted race-window optimization.

Researcher Lee Jia Jie (STAR Labs, Singapore) — in his first Linux kernel research effort, done during an internship — stated AI assisted with vulnerability discovery, KASAN proof-of-concept generation, and race-condition timing optimization, while cautioning that "AI still has many blind spots and lapses in reasoning ability" and that manual analysis remained essential for exploitation logic and real-world validation. Separately, Kyle Zeng (handle KyleBot) used an AI-assisted research system to independently discover and report the same CVE-2026-53264 bug roughly two days ahead of Lee, shortly before the TyphoonPwn 2026 competition (TyphoonCon, Seoul, 2026-05-25 through 2026-05-29); Zeng is credited as reporter in the upstream patch. Lee's STAR Labs submission placed 8th of 11 entrants in TyphoonPwn 2026's Linux Privilege Escalation category (prize pool up to $70,000), which closed after three winners were awarded. The original technical write-up underlying much of the derivative press coverage was published on Slippy Blog.

The same AI-assisted research pipeline also surfaced CVE-2026-64300, an unrelated use-after-free in the kernel's perf events subsystem (kernel/events/core.c): two perf events made to share a ring buffer via the PERF_EVENT_IOC_SET_OUTPUT ioctl can race during mmap, and map_range() reads auxiliary ring-buffer fields under only per-event locking instead of the required ring-buffer-level synchronization, so a page can be freed while still mapped. CVE-2026-64300 affects Linux 6.14 and later, is fixed in 6.18.39, 7.1.4, and 7.2-rc3, and was reported to disproportionately affect Intel bare-metal systems on RHEL-based and Arch desktop distributions (not Debian-based systems).

A public PoC for CVE-2026-53264 (Makefile, dmesg_msr_kaslr.c/.h, poc.c, pwn_utils.cpp/.h) is published at github.com/star-sg/CVE. As of 2026-07-28, Debian lists fixed kernels for its supported stable releases, but Ubuntu still marks multiple maintained kernel packages vulnerable and SUSE lists the issue as pending across multiple products — notably, SUSE's own severity assessment diverges from NVD's, rating the bug CVSS 5.5 versus NVD's 7.8. Neither CVE-2026-53264 nor CVE-2026-64300 appears in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

## MITRE ATT&CK

- T1587.004 Exploits
- T1588.005 Exploits
- T1588.006 Vulnerabilities
- T1588.002 Tool
- T1059.004 Unix Shell
- T1106 Native API
- T1068 Exploitation for Privilege Escalation
- T1546 Event Triggered Execution
- T1611 Escape to Host
- T1211 Exploitation for Stealth
- T1620 Reflective Code Loading
- T1082 System Information Discovery
- T1588.007 Artificial Intelligence
- T1027.011 Fileless Storage
- T1005 Data from Local System
- T1608.002 Stage Capabilities: Upload Tool

## Sources

- [Infosecurity Magazine: AI Linux Kernel Zero-Day (net/sched)](https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/)
- [The Hacker News: Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit](https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html)
- [NVD - CVE-2026-53264](https://nvd.nist.gov/vuln/detail/CVE-2026-53264)
- [NVD - CVE-2026-64300](https://nvd.nist.gov/vuln/detail/CVE-2026-64300)
- [STAR Labs CVE-2026-53264 Proof-of-Concept (GitHub)](https://github.com/star-sg/CVE/tree/master/CVE-2026-53264)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [TyphoonPwn 2026 (TyphoonCon)](https://typhooncon.com/typhoonpwn-2026/)
- [Cryptika Cybersecurity: AI-Assisted Research Uncovers Linux Kernel Zero-Day Enabling Root Privilege Escalation](https://www.cryptika.com/ai-assisted-research-uncovers-linux-kernel-zero-day-enabling-root-privilege-escalation/)
- [GuardianMSSP: Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit](https://www.guardianmssp.com/2026/07/28/researcher-says-ai-helped-develop-linux-traffic-control-race-into-root-exploit/)
- [Kyle Zeng (KyleBot) — personal site](https://www.kylebot.net/)
- [git.kernel.org: fix commit for CVE-2026-53264](https://git.kernel.org/stable/c/5057e1aca011e51ef51498c940ef96f3d3e8a305)
- [git.kernel.org: fix commit for CVE-2026-64300](https://git.kernel.org/stable/c/0cff05bd2186020f8706233e261016d149cc24db)
- [Slippy Blog: original technical write-up of Lee Jia Jie's AI-assisted CVE-2026-53264 exploitation](https://slippy.blog/)
- [MITRE ATT&CK T1620 - Reflective Code Loading](https://attack.mitre.org/techniques/T1620/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1744
