PoC Exploit Published for DirtyDecrypt Linux Kernel Flaw
ID: 77143644-2d14-5279-b489-9dcf01cc00b2
STIX ID: report--77143644-2d14-5279-b489-9dcf01cc00b2
Feed Name: Cyber Press
A publicly released proof-of-concept for DirtyDecrypt (linked to CVE-2026-31635) enables local privilege escalation to root by exploiting a missing copy-on-write guard in the Linux kernel RxGK subsystem (rxgk_decrypt_skb). The PoC, validated on Fedora and mainline kernels, can corrupt privileged page-cache pages (e.g., /etc/shadow or SUID binaries) and is particularly dangerous for containerized workloads where a compromised pod could escape to host root; mitigations include applying the upstream kernel fix or blacklisting affected modules (esp4, esp6, rxrpc).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
