Overview

Our member discovered a local privilege escalation 0-day vulnerability on the latest Linux kernel that allows an unprivileged user to obtain root privileges.

Privilege escalation demonstrated on CentOS Stream 9
Privilege escalation demonstrated on CentOS Stream 9

The Vulnerability

The exploit chains together two Linux kernel bugs to allow an unprivileged user to obtain root privileges. The proof of concept was demonstrated on a default installation of CentOS Stream 9 running on real hardware, however the underlying issue resides in the Linux kernel itself and is not specific to CentOS, so other major distributions are similarly affected.

In line with a coordinated disclosure process, technical details of this vulnerability, including the affected components and the proof of concept, are withheld until the vendor's fix is released and a CVE is assigned. A full technical writeup will be published after the fix is in place.

A Hybrid Approach Combining AI and Human Expertise

The vulnerability research and exploit chain construction for this case were carried out through a hybrid approach combining LLM-driven broad exploration with hands-on analysis and implementation by our member. The LLM handled wide-ranging candidate search and pattern extraction, while in-depth verification grounded in kernel internals and the refinement of the exploit itself were handled by the member.

Kernel privilege escalation rarely succeeds with a single bug. In many cases it only becomes possible by combining multiple primitives. Both machine-scale broad exploration and human structural understanding are therefore essential. We see chains like this two-bug construction as something only reachable when AI and human expertise are organized to complement each other's strengths.

Ongoing Vulnerability Research

We have developed a proprietary approach that leverages LLMs for vulnerability research, and we will continue conducting 0-day research on major software including the Linux kernel. Based on this hands-on vulnerability discovery expertise, we provide AI-driven security assessment and consulting services. If you are interested, please feel free to contact us.