logo

DirtyDecrypt: PoC Released for yet another Linux flaw

ID: 5913f083-c4f6-57df-a5ca-5a64aff52bb4

STIX ID: report--5913f083-c4f6-57df-a5ca-5a64aff52bb4

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Pierluigi Paganini

...
...

DirtyDecrypt (CVE-2026-31635) is a local Linux kernel privilege escalation caused by a missing copy-on-write guard in rxgk_decrypt_skb; a working proof-of-concept has been published. The bug allows decryption writes to land in shared page-cache pages (e.g., /etc/shadow or SUID binaries), enabling privilege escalation on kernels built with CONFIG_RXGK (notably Fedora, Arch, and openSUSE), and may enable container escapes in clustered environments; administrators should check kernel configs and apply patches promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.