Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
A researcher, aided by AI, discovered and developed a Linux kernel exploit (CVE-2026-53264) that allows a local user to gain root access on CentOS Stream 9. The exploit leverages a use-after-free race in the network traffic-control subsystem and requires specific kernel options and namespaces. While the immediate risk is somewhat limited due to the specific conditions needed, the public availability of the exploit code necessitates urgent patching for compatible systems. The vulnerability was initially discovered independently by Lee Jia Jie, with Kyle Zeng reporting it shortly before the TyphoonPwn 2026 competition, and AI significantly aided the process of finding and developing the exploit.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
