logo

Exploit available for new DirtyDecrypt Linux root escalation flaw

ID: 28cf5959-7ea1-5aa2-95e9-8b2acd0d0546

STIX ID: report--28cf5959-7ea1-5aa2-95e9-8b2acd0d0546

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Sergiu Gatlan

...
...

A local privilege-escalation flaw in the Linux kernel rxgk module (called DirtyDecrypt/DirtyCBC and linked to CVE-2026-31635) has a public proof-of-concept that can grant root on systems built with CONFIG_RXGK enabled; the issue was patched upstream and mainly affects distros tracking mainline kernels (e.g., Fedora, Arch, openSUSE Tumbleweed). Administrators are advised to apply kernel updates or use the provided module-blacklisting mitigation (which may break IPsec and AFS) until patches are deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.