DirtyDecrypt: PoC Released for yet another Linux flaw
ID: 5913f083-c4f6-57df-a5ca-5a64aff52bb4
STIX ID: report--5913f083-c4f6-57df-a5ca-5a64aff52bb4
Feed Name: Security Affairs
DirtyDecrypt (CVE-2026-31635) is a local Linux kernel privilege escalation caused by a missing copy-on-write guard in rxgk_decrypt_skb; a working proof-of-concept has been published. The bug allows decryption writes to land in shared page-cache pages (e.g., /etc/shadow or SUID binaries), enabling privilege escalation on kernels built with CONFIG_RXGK (notably Fedora, Arch, and openSUSE), and may enable container escapes in clustered environments; administrators should check kernel configs and apply patches promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
