CVE-2026-31635 (DirtyDecrypt) Linux Kernel Privilege Escalation Explained
ID: 7a741089-8cd2-52ab-b08d-9accb8ae8485
STIX ID: report--7a741089-8cd2-52ab-b08d-9accb8ae8485
Feed Name: Picus Security Articles
**Executive Summary:** CVE-2026-31635 (DirtyDecrypt / DirtyCBC) is a Linux kernel local privilege-escalation vulnerability in the AF_RXRPC RxGK security layer that lets a local attacker, who supplies the encryption key and crafts spliced packets, cause in-place CBC decryption to overwrite page-cache contents of a readable SUID-root binary and then execute it to gain root; the report details the root cause, the five-step exploitation sequence, affected kernel components, and simulation guidance via the Picus Platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
