logo

PoC Exploit Published for DirtyDecrypt Linux Kernel Flaw

ID: 77143644-2d14-5279-b489-9dcf01cc00b2

STIX ID: report--77143644-2d14-5279-b489-9dcf01cc00b2

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Lucas Martin

...
...

A publicly released proof-of-concept for DirtyDecrypt (linked to CVE-2026-31635) enables local privilege escalation to root by exploiting a missing copy-on-write guard in the Linux kernel RxGK subsystem (rxgk_decrypt_skb). The PoC, validated on Fedora and mainline kernels, can corrupt privileged page-cache pages (e.g., /etc/shadow or SUID binaries) and is particularly dangerous for containerized workloads where a compromised pod could escape to host root; mitigations include applying the upstream kernel fix or blacklisting affected modules (esp4, esp6, rxrpc).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.