DirtyDecrypt PoC (CVE-2026-31635): Linux Kernel LPE via rxgk Missing COW Guard
Technical exploit breakdown of DirtyDecrypt: achieving local root privilege escalation via missing Copy-On-Write guards in Linux rxgk.
CVE-2026-31635
Severity: CVSS 7.8
Target Component: Linux Kernel rxgk subsystem
CVE-2026-31635 (CVSS 7.5), dubbed DirtyDecrypt (aka DirtyCBC), is a Linux kernel local privilege escalation vulnerability discovered by the Zellic and V12 security teams. A public PoC has been released. The flaw affects only distributions with CONFIG_RXGK enabled, including Fedora, Arch Linux, and openSUSE Tumbleweed.
Technical Details
The vulnerability is a missing copy-on-write (COW) guard in rxgk_decrypt_skb(), the function that decrypts incoming socket buffers in the AFS/rxgk kernel subsystem. Under normal Linux kernel memory management, when a write to a page shared with other processes occurs, a COW guard ensures a private copy is made first — preventing the write from affecting another process's data.
Without this guard in rxgk_decrypt_skb(), decrypted data gets written directly to memory pages shared with privileged processes or to the page cache of privileged files. An attacker can exploit this primitive to overwrite the contents of:
/etc/shadow— modifying password hashes/etc/sudoers— adding a NOPASSWD entry- SUID binaries — injecting shellcode into a root-owned executable
This constitutes a full local privilege escalation to root.
Relationship to Copy Fail Trilogy
DirtyDecrypt is the fourth member of the Linux kernel page cache write primitive family discovered in 2026:
- Copy Fail / CVE-2026-31431 — AF_ALG cryptographic socket interface (Theori, April 29)
- Dirty Frag / CVE-2026-43284 & CVE-2026-43500 — XFRM ESP-in-UDP MSG_SPLICE_PAGES
- Fragnesia / CVE-2026-46300 — XFRM ESP-in-TCP subsystem
- DirtyDecrypt / CVE-2026-31635 — rxgk AFS subsystem (this disclosure)
Affected Distributions
Only kernels compiled with CONFIG_RXGK=y are vulnerable:
- Fedora — CONFIG_RXGK enabled by default
- Arch Linux — CONFIG_RXGK enabled by default
- openSUSE Tumbleweed — CONFIG_RXGK enabled by default
- Container environments: vulnerable worker nodes provide a potential pod escape path
Ubuntu, Debian, RHEL, and derivatives do not enable CONFIG_RXGK by default and are not affected.
Check Exposure
grep CONFIG_RXGK /boot/config-$(uname -r)
# CONFIG_RXGK=y means vulnerable; # CONFIG_RXGK is not set means safeRemediation
- Apply the latest kernel update from your distribution — the mainline fix has been merged.
- If an updated kernel is not yet available, disable the rxgk module:
echo "install rxgk /bin/true" >> /etc/modprobe.d/disable-rxgk.conf && update-initramfs -u - Rocky Linux users can enable the optional security repository for accelerated patching:
dnf config-manager --enable rocky-security - Arch Linux:
sudo pacman -Syu linux linux-headers - Fedora:
sudo dnf update kernel - openSUSE Tumbleweed:
sudo zypper up kernel-default
← Back to the Security Roundup: Week of May 28, 2026