New DirtyDecrypt Linux Flaw Exploit Released, Patching Urged

New DirtyDecrypt Linux Flaw Exploit Released, Patching Urged

First seen 18 May 2026, 15:56 UTC Bleepingcomputernvd.nist.govdocs.kernel.orgCybersecuritynewsGbhackers+2 93% similarity 72.0

Article Content

Browse articles
ThreatCluster

A local privilege escalation vulnerability in the Linux kernel's rxgk module, named DirtyDecrypt, has been discovered and a proof-of-concept exploit is now available. The V12 security team reported this flaw on May 9, 2026, but it was identified as a duplicate of CVE-2026-31635, which was patched on April 25. Successful exploitation requires the CONFIG_RXGK option enabled, affecting distributions like Fedora, Arch Linux, and openSUSE Tumbleweed. Users are advised to update their kernels immediately, as the exploit poses significant risks. The vulnerability is part of a series of recent root escalation flaws, including Dirty Frag and Copy Fail, which are actively being exploited. The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies to secure their Linux devices promptly.

Key Points: • DirtyDecrypt is a local privilege escalation vulnerability in the Linux kernel's rxgk module. • A proof-of-concept exploit has been released, affecting distributions like Fedora and Arch Linux. • Users are urged to patch their systems immediately to mitigate risks from this vulnerability.

ThreatCluster AI

Timeline

2026-04-24
CVE-2026-31635 published
CVE-2026-31635, related to the DirtyDecrypt flaw, was published and patched on April 25.
BleepingComputer
2026-05-01
CISA adds Copy Fail to exploited vulnerabilities list
CISA confirmed that the Copy Fail vulnerability is being actively exploited and ordered federal agencies to secure Linux devices.
BleepingComputer
2026-05-09
V12 reports DirtyDecrypt vulnerability
The V12 security team reported the DirtyDecrypt flaw, which was later identified as a duplicate of an already patched vulnerability.
BleepingComputer
2026-05-15
Deadline for federal agencies to secure devices
CISA mandated that federal agencies secure their Linux devices against the Copy Fail vulnerability by this date.
BleepingComputer
2026-05-18
Exploit for DirtyDecrypt made public
A proof-of-concept exploit for the DirtyDecrypt vulnerability was released, prompting urgent patching recommendations.
BleepingComputer

Community

Browse all →