A new vulnerability in the Linux kernel that allows local privilege escalation is causing significant concern in the cybersecurity community, with a proof-of-concept exploit (which can grant full root access to affected systems) already circulating. The vulnerability, known as “ DirtyDecrypt ” or “ DirtyCBC ,” affects the Linux kernel’s rxgk module and is part of a growing list of serious privilege escalation flaws that have been revealed in recent months.

The issue was discovered by the V12, who revealed that the vulnerability had already been fixed in the upstream kernel version before their report was even made public. Although no official CVE identifier has been assigned, several experts believe that it is directly related to CVE-2026-31635, which was updated in late April.
The emergence of a functional exploit significantly increases the level of risk, especially in Linux distributions that aggressively follow the latest upstream kernel versions.
What is DirtyDecrypt and how does it work?
According to the technical details released by V12, the vulnerability results from incorrect pagecache management of entries in the rxgk module, due to the absence of Copy-On-Write (COW guard) protection in the “rxgk_decrypt_skb” function.
See also: Claw Chain: OpenClaw vulnerabilities allow complete system compromise
Simply put, the flaw allows a local user to affect critical kernel memory structures and gain elevated privileges through manipulation of the page cache.
The proof-of-concept exploit published by V12 shows that an attacker can gain root shell on certain Linux configurations without requiring physical access or complex interaction with the system.
This particular category of vulnerabilities is considered particularly dangerous, as privilege escalation attacks are often used as a second stage after an initial breach of a user account or service.

Which Linux distributions are affected?
The vulnerability does not affect all Linux systems equally. To be exploitable, the kernel requires the CONFIG_RXGK option to be enabled , which provides RxGK security support for the Andrew File System (AFS) client and certain network functions .
This theoretically limits the attack surface to distributions that closely follow the latest upstream versions of the Linux kernel. Among the potentially affected distributions are Fedora, Arch Linux, and openSUSE Tumbleweed.
The V12 team confirmed that the exploit was successfully tested on both Fedora and mainline Linux kernel builds.
Although enterprise distributions like Ubuntu LTS or Debian Stable may not be directly exposed due to different kernel configurations, experts warn that the situation could change depending on custom installations or backported features.
The new “family” of Linux vulnerabilities
DirtyDecrypt is not an isolated incident. Rather, it joins a series of similar vulnerabilities that have been recently identified in the Linux kernel.
Among the most well-known are Dirty Frag, Fragnesia, and Copy Fail — vulnerabilities that also exploit memory management and page cache issues for privilege escalation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: MiniPlasma: New Windows zero-day worries admins
Experts note that the continued emergence of such vulnerabilities shows that the Linux kernel continues to face complex security issues in low-level mechanisms, particularly in areas related to memory management and network subsystems.
The situation has begun to seriously concern the security community, as root escalation attacks can turn even a small user breach into a full compromise of the entire operating system.

Temporary solutions and risks for production environments
Maintainers and researchers recommend that users install the latest kernel updates immediately. However, in environments where upgrading is not immediately possible, a temporary mitigation is recommended that disables specific modules such as esp4, esp6, and rxrpc.
This solution reduces the attack surface, but comes with serious side effects. Specifically, it can cause problems with VPN connections and distributed AFS file systems.
For enterprise environments that rely on such services, implementing mitigation may create major operational problems, making the situation difficult to manage.
CISA warns of active attacks
The DirtyDecrypt revelation comes at a time when US cybersecurity authorities have already sounded the alarm about Linux privilege escalation flaws. The US Cybersecurity and Infrastructure Security Agency (CISA) recently added the “Copy Fail” vulnerability to its Known Exploited Vulnerabilities list, confirming that it is being actively used in real-world attacks.
See also: NGINX: Critical vulnerability used in attacks
At the same time, the agency ordered all federal agencies to secure their Linux systems within two weeks, emphasizing that such vulnerabilities are now a key tool for cyberattacks.
Experts believe that attackers are increasingly turning to Linux privilege escalation exploits because Linux systems dominate cloud infrastructures, data centers, and high-value enterprise environments.

Linux is facing a difficult security period
The DirtyDecrypt case adds to a series of worrying revelations surrounding the security of the Linux ecosystem.
Just last month, Linux distributions released patches for “Pack2TheRoot,” a privilege escalation vulnerability in the PackageKit daemon that had remained unseen for nearly 12 years.
The fact that critical root-level flaws continue to be discovered in fundamental Linux components shows how difficult it has become to maintain security in modern kernels that include millions of lines of code and dozens of different subsystems.
Although Linux is still considered one of the most secure operating systems, the increase in sophisticated kernel exploits proves that even open-source ecosystems are not immune to modern cybersecurity threats.
Source: www.bleepingcomputer.com
