HomeSecurityDirtyDecrypt: PoC exploit released for Linux vulnerability

DirtyDecrypt: PoC exploit for Linux vulnerability released

A new vulnerability in the Linux kernel that allows local privilege escalation is causing significant concern in the cybersecurity community, with a proof-of-concept exploit (which can grant full root access to affected systems) already circulating. The vulnerability, known as “ DirtyDecrypt ” or “ DirtyCBC ,” affects the Linux kernel’s rxgk module and is part of a growing list of serious privilege escalation flaws that have been revealed in recent months.

DirtyDecrypt Linux

The issue was discovered by the V12, who revealed that the vulnerability had already been fixed in the upstream kernel version before their report was even made public. Although no official CVE identifier has been assigned, several experts believe that it is directly related to CVE-2026-31635, which was updated in late April.

The emergence of a functional exploit significantly increases the level of risk, especially in Linux distributions that aggressively follow the latest upstream kernel versions.

What is DirtyDecrypt and how does it work?

According to the technical details released by V12, the vulnerability results from incorrect pagecache management of entries in the rxgk module, due to the absence of Copy-On-Write (COW guard) protection in the “rxgk_decrypt_skb” function.

See also: Claw Chain: OpenClaw vulnerabilities allow complete system compromise

Simply put, the flaw allows a local user to affect critical kernel memory structures and gain elevated privileges through manipulation of the page cache.

The proof-of-concept exploit published by V12 shows that an attacker can gain root shell on certain Linux configurations without requiring physical access or complex interaction with the system.

This particular category of vulnerabilities is considered particularly dangerous, as privilege escalation attacks are often used as a second stage after an initial breach of a user account or service.

DirtyDecrypt: PoC exploit for Linux vulnerability released

Which Linux distributions are affected?

The vulnerability does not affect all Linux systems equally. To be exploitable, the kernel requires the CONFIG_RXGK option to be enabled , which provides RxGK security support for the Andrew File System (AFS) client and certain network functions .

This theoretically limits the attack surface to distributions that closely follow the latest upstream versions of the Linux kernel. Among the potentially affected distributions are Fedora, Arch Linux, and openSUSE Tumbleweed.

The V12 team confirmed that the exploit was successfully tested on both Fedora and mainline Linux kernel builds.

Although enterprise distributions like Ubuntu LTS or Debian Stable may not be directly exposed due to different kernel configurations, experts warn that the situation could change depending on custom installations or backported features.

The new “family” of Linux vulnerabilities

DirtyDecrypt is not an isolated incident. Rather, it joins a series of similar vulnerabilities that have been recently identified in the Linux kernel.

Among the most well-known are Dirty Frag, Fragnesia, and Copy Fail — vulnerabilities that also exploit memory management and page cache issues for privilege escalation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: MiniPlasma: New Windows zero-day worries admins

Experts note that the continued emergence of such vulnerabilities shows that the Linux kernel continues to face complex security issues in low-level mechanisms, particularly in areas related to memory management and network subsystems.

The situation has begun to seriously concern the security community, as root escalation attacks can turn even a small user breach into a full compromise of the entire operating system.

DirtyDecrypt: PoC exploit for Linux vulnerability released

Temporary solutions and risks for production environments

Maintainers and researchers recommend that users install the latest kernel updates immediately. However, in environments where upgrading is not immediately possible, a temporary mitigation is recommended that disables specific modules such as esp4, esp6, and rxrpc.

This solution reduces the attack surface, but comes with serious side effects. Specifically, it can cause problems with VPN connections and distributed AFS file systems.

For enterprise environments that rely on such services, implementing mitigation may create major operational problems, making the situation difficult to manage.

CISA warns of active attacks

The DirtyDecrypt revelation comes at a time when US cybersecurity authorities have already sounded the alarm about Linux privilege escalation flaws. The US Cybersecurity and Infrastructure Security Agency (CISA) recently added the “Copy Fail” vulnerability to its Known Exploited Vulnerabilities list, confirming that it is being actively used in real-world attacks.

See also: NGINX: Critical vulnerability used in attacks

At the same time, the agency ordered all federal agencies to secure their Linux systems within two weeks, emphasizing that such vulnerabilities are now a key tool for cyberattacks.

Experts believe that attackers are increasingly turning to Linux privilege escalation exploits because Linux systems dominate cloud infrastructures, data centers, and high-value enterprise environments.

DirtyDecrypt: PoC exploit for Linux vulnerability released

Linux is facing a difficult security period

The DirtyDecrypt case adds to a series of worrying revelations surrounding the security of the Linux ecosystem.

Just last month, Linux distributions released patches for “Pack2TheRoot,” a privilege escalation vulnerability in the PackageKit daemon that had remained unseen for nearly 12 years.

The fact that critical root-level flaws continue to be discovered in fundamental Linux components shows how difficult it has become to maintain security in modern kernels that include millions of lines of code and dozens of different subsystems.

Although Linux is still considered one of the most secure operating systems, the increase in sophisticated kernel exploits proves that even open-source ecosystems are not immune to modern cybersecurity threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS