Skip to content

Linux Exploit CVE-2026-53264: Race Condition in Traffic Control Subsystem

Bottom line: CVE-2026-53264 (CVSS 7.8) enables local privilege escalation through a race condition whose exploit was developed with AI assistance.

Researchers from STAR Labs have published a Linux kernel exploit that escalates local users to root privileges on CentOS Stream 9. The use-after-free race condition in the network traffic control subsystem was developed in part with AI support.

The security research team STAR Labs has released a functional exploit for the vulnerability CVE-2026-53264. The vulnerability with a CVSS score of 7.8 exists in the kernel subsystem for network traffic control and allows a local user to escalate to root privileges. The attack exploits a use-after-free race condition.

Researcher Lee Jia Jie reports that artificial intelligence assisted both in identifying the bug and in accelerating exploit development. This illustrates a growing role of AI tools in the analysis of kernel code and the discovery of critical security vulnerabilities in operating systems.

For CISOs: The vulnerability requires local access and specifically affects CentOS Stream 9 systems. Organizations should verify whether they are running Linux kernel versions with this vulnerability and apply updates as soon as they become available. The exploit also demonstrates that even complex kernel vulnerabilities can be identified more quickly through AI-assisted analysis procedures – a factor that security teams should consider in their incident response planning.


Source: thehackernews.com · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: