DirtyDecrypt PoC (CVE-2026-31635): Linux Kernel LPE via rxgk Missing COW Guard

Technical exploit breakdown of DirtyDecrypt: achieving local root privilege escalation via missing Copy-On-Write guards in Linux rxgk.

DirtyDecrypt PoC (CVE-2026-31635): Linux Kernel LPE via rxgk Missing COW Guard
📌
Security Roundup Series: Week of May 28, 2026 • 4 min read deep dive
⚠️
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-31635 Severity: CVSS 7.8 Target Component: Linux Kernel rxgk subsystem

CVE-2026-31635 (CVSS 7.5), dubbed DirtyDecrypt (aka DirtyCBC), is a Linux kernel local privilege escalation vulnerability discovered by the Zellic and V12 security teams. A public PoC has been released. The flaw affects only distributions with CONFIG_RXGK enabled, including Fedora, Arch Linux, and openSUSE Tumbleweed.

Technical Details

The vulnerability is a missing copy-on-write (COW) guard in rxgk_decrypt_skb(), the function that decrypts incoming socket buffers in the AFS/rxgk kernel subsystem. Under normal Linux kernel memory management, when a write to a page shared with other processes occurs, a COW guard ensures a private copy is made first — preventing the write from affecting another process's data.

Without this guard in rxgk_decrypt_skb(), decrypted data gets written directly to memory pages shared with privileged processes or to the page cache of privileged files. An attacker can exploit this primitive to overwrite the contents of:

  • /etc/shadow — modifying password hashes
  • /etc/sudoers — adding a NOPASSWD entry
  • SUID binaries — injecting shellcode into a root-owned executable

This constitutes a full local privilege escalation to root.

Relationship to Copy Fail Trilogy

DirtyDecrypt is the fourth member of the Linux kernel page cache write primitive family discovered in 2026:

  • Copy Fail / CVE-2026-31431 — AF_ALG cryptographic socket interface (Theori, April 29)
  • Dirty Frag / CVE-2026-43284 & CVE-2026-43500 — XFRM ESP-in-UDP MSG_SPLICE_PAGES
  • Fragnesia / CVE-2026-46300 — XFRM ESP-in-TCP subsystem
  • DirtyDecrypt / CVE-2026-31635 — rxgk AFS subsystem (this disclosure)

Affected Distributions

Only kernels compiled with CONFIG_RXGK=y are vulnerable:

  • Fedora — CONFIG_RXGK enabled by default
  • Arch Linux — CONFIG_RXGK enabled by default
  • openSUSE Tumbleweed — CONFIG_RXGK enabled by default
  • Container environments: vulnerable worker nodes provide a potential pod escape path

Ubuntu, Debian, RHEL, and derivatives do not enable CONFIG_RXGK by default and are not affected.

Check Exposure

grep CONFIG_RXGK /boot/config-$(uname -r)
# CONFIG_RXGK=y means vulnerable; # CONFIG_RXGK is not set means safe

Remediation

  • Apply the latest kernel update from your distribution — the mainline fix has been merged.
  • If an updated kernel is not yet available, disable the rxgk module: echo "install rxgk /bin/true" >> /etc/modprobe.d/disable-rxgk.conf && update-initramfs -u
  • Rocky Linux users can enable the optional security repository for accelerated patching: dnf config-manager --enable rocky-security
  • Arch Linux: sudo pacman -Syu linux linux-headers
  • Fedora: sudo dnf update kernel
  • openSUSE Tumbleweed: sudo zypper up kernel-default

← Back to the Security Roundup: Week of May 28, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther