Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Exploit releasedLinux kernelCentOS Stream 9Our summary
A researcher from STAR Labs has published a local privilege escalation exploit targeting a vulnerability in the Linux kernel, specifically affecting CentOS Stream 9. The flaw, identified as CVE-2026-53264, involves a use-after-free race condition within the traffic-control subsystem. According to the researcher, AI played a significant role in identifying the bug and accelerating the development of the exploit. While the exploit requires specific configurations such as unprivileged user namespaces and certain kernel options, the release of full source code increases the urgency for affected systems to apply patches. An upstream fix was introduced on June 1, 2026, and has been backported to various stable branches.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.