Bleepingcomputer
New DirtyDecrypt Linux Flaw Exploit Released, Patching Urged
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A local privilege escalation vulnerability in the Linux kernel's rxgk module, named DirtyDecrypt, has been discovered and a proof-of-concept exploit is now available. The V12 security team reported this flaw on May 9, 2026, but it was identified as a duplicate of CVE-2026-31635, which was patched on April 25. Successful exploitation requires the CONFIG_RXGK option enabled, affecting distributions like Fedora, Arch Linux, and openSUSE Tumbleweed. Users are advised to update their kernels immediately, as the exploit poses significant risks. The vulnerability is part of a series of recent root escalation flaws, including Dirty Frag and Copy Fail, which are actively being exploited. The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies to secure their Linux devices promptly.
Key Points: • DirtyDecrypt is a local privilege escalation vulnerability in the Linux kernel's rxgk module. • A proof-of-concept exploit has been released, affecting distributions like Fedora and Arch Linux. • Users are urged to patch their systems immediately to mitigate risks from this vulnerability.