CVE-2026-31635PoC(linux / linux_kernel)

CRITICALCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the packet and is supposed to verify that it fits in the remaining bytes. The existing check is inverted, so oversized RESPONSE authenticators are accepted and passed to rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an impossible length and hit BUG_ON(len). Decoded from the original latest-net reproduction logs with scripts/decode_stacktrace.sh: RIP: __skb_to_sgvec() [net/core/skbuff.c:5285 (discriminator 1)] Call Trace: skb_to_sgvec() [net/core/skbuff.c:5305] rxgk_decrypt_skb() [net/rxrpc/rxgk_common.h:81] rxgk_verify_response() [net/rxrpc/rxgk.c:1268] rxrpc_process_connection() [net/rxrpc/conn_event.c:266 net/rxrpc/conn_event.c:364 net/rxrpc/conn_event.c:386] process_one_work() [kernel/workqueue.c:3281] worker_thread() [kernel/workqueue.c:3353 kernel/workqueue.c:3440] kthread() [kernel/kthread.c:436] ret_from_fork() [arch/x86/kernel/process.c:164] Reject authenticator lengths that exceed the remaining packet payload.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 70 mentions across 18 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 31 signals
  • PoC mentioned or linked in 57 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 59 signals
  • Disclosure: 9 classified signals
  • General: 4 classified signals
  • Peaked 15d ago at 29 mentions (2026-05-19); latest day: 1
  • 70 total mentions across 18 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline70 mentions / 18d
07152229Mentions · 2026-04-24: 1Mentions · 2026-05-18: 4Mentions · 2026-05-19: 29Mentions · 2026-05-20: 17Mentions · 2026-05-21: 4Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1Mentions · 2026-05-25: 1Mentions · 2026-05-26: 2Mentions · 2026-06-02: 1Mentions · 2026-06-06: 2Mentions · 2026-06-07: 1Mentions · 2026-08-07: 1Mentions · 2026-08-10: 1Mentions · 2026-08-13: 1Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-05-18: 3PoC Mentioned / Linked · 2026-05-19: 27PoC Mentioned / Linked · 2026-05-20: 13PoC Mentioned / Linked · 2026-05-21: 4PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-06-06: 2PoC Mentioned / Linked · 2026-06-07: 1PoC Mentioned / Linked · 2026-08-10: 1PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-05-18: 2Exploit Tool / Code · 2026-05-19: 17Exploit Tool / Code · 2026-05-20: 4Exploit Tool / Code · 2026-05-21: 2Exploit Tool / Code · 2026-05-26: 1Exploit Tool / Code · 2026-06-06: 2Exploit Tool / Code · 2026-06-07: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-18: 1Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-19: 5Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-06-06: 2Technical Details · 2026-04-24: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-19: 24Technical Details · 2026-05-20: 16Technical Details · 2026-05-21: 4Technical Details · 2026-05-23: 1Technical Details · 2026-05-26: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-06: 2Technical Details · 2026-08-07: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 1Technical Details · 2026-09-11: 104-2405-1805-1905-2005-2105-2205-2305-2505-2606-0206-0606-0708-0708-1008-1308-1708-1809-11
Signal classification6 categories
PoC
5071.4%
Disclosure
912.9%
General
45.7%
Patch
34.3%
Exploit
34.3%
Active Exploitation
11.4%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-241
Patch1
2026-05-184
Exploit2General1PoC1
2026-05-1929
Active Exploitation1Disclosure1Patch1PoC26
2026-05-2017
Disclosure4Exploit1Patch1PoC11
2026-05-214
PoC4
2026-05-221
General1
2026-05-231
PoC1
2026-05-251
General1
2026-05-262
Disclosure1PoC1
2026-06-021
Disclosure1
2026-06-062
PoC2
2026-06-071
PoC1
2026-08-071
Disclosure1
2026-08-101
PoC1
2026-08-131
PoC1
2026-08-171
Disclosure1
2026-08-181
PoC1
2026-09-111
General1
Full discourse20 posts
  • zack0x01@zack0x01_
    PoC

    🚨 Public PoC exploit code has been released for DirtyDecrypt, a now-patched Linux kernel vulnerability tracked as CVE-2026-31635 that may enable local privilege escalation. The flaw impacts systems with CONFIG_RXGK enabled, including Fedora, Arch Linux, and openSUSE Tumbleweed.

    Post summary

    A public PoC exploit code for CVE-2026-31635, enabling local privilege escalation on Linux kernels with CONFIG_RXGK, has been released, although the vulnerability is now patched on affected systems.

    335124912320.8K
    3.2K followersView on X
  • The Hacker News@TheHackersNews
    PoC

    🚨 Public PoC exploit code is out for DirtyDecrypt, a patched Linux kernel flaw linked to CVE-2026-31635 that could allow local privilege escalation. It affects CONFIG_RXGK-enabled systems, including Fedora, Arch Linux, and openSUSE Tumbleweed. Details: https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html

    Post summary

    A public PoC exploit code for CVE-2026-31635 has been released, highlighting a kernel flaw that permits local privilege escalation on CONFIG_RXGK-enabled systems.

    35351696255.9K
    1.9M followersView on X
  • elhacker.NET@elhackernet
    PoC

    Publicado exploit PoC de vulnerabilidad DirtyDecrypt en kernel de Linux Se ha publicado un código de prueba de concepto (PoC) para DirtyDecrypt (también conocido como DirtyCBC), una vulnerabilidad de alta gravedad en el núcleo de Linux. CVE-2026-31635, permite que atacantes locales obtengan acceso total de root https://blog.elhacker.net/2026/05/publicado-exploit-poc-de-vulnerabilidad.html

    Post summary

    A proof‑of‑concept for the DirtyDecrypt (DirtyCBC) Linux kernel privilege escalation (CVE‑2026‑31635) has been published, giving local attackers root access. No active exploitation, patch information, or debunking are mentioned.

    1451144497.8K
    141.0K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    ثغرة جديدة في نواة لينكس باسم DirtyDecrypt أو DirtyCBC 🙃 تنضم إلى سلسلة ثغرات رفع الصلاحيات LPE في نواة لينكس المتكشفه هالشهر. رقم الثغرة CVE-2026-31635 هذي رابع ثغرة (LPE) من نفس العائلة و نفس نمط في ٣ اسابيع التفاصيل التقنية: 👇 https://t.co/oLw8tXVvxs

    Post summary

    The post announces a new Linux kernel privilege‑elevation bug named DirtyDecrypt/DirtyCBC (CVE‑2026‑31635) and provides a link to further technical details.

    271683612.7K
    50.0K followersView on X
  • Hack32@Hack32_
    Disclosure

    DirtyDecrypt (CVE-2026-31635) is a local privilege escalation vulnerability in the Linux kernel's rxrpc subsystem (specifically the rxgk component). https://github.com/0xBlackash/CVE-2026-31635

    Post summary

    DirtyDecrypt (CVE-2026-31635) is a newly disclosed local privilege escalation vulnerability in the Linux kernel's rxrpc subsystem, with a GitHub repository linked for a proof‑of‑concept exploit.

    07157284.7K
    828 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    PoC

    DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html?m=1

    Post summary

    A proof‑of‑concept for the Linux Kernel CVE‑2026‑31635 local privilege escalation vulnerability has been released and announced via a news article.

    040279904
    17.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Linux Kernel'de CVE-2026-31635 | CVSS 7.5 için Public PoC/Exploit RXRPC/RXGK bileşenindeki zafiyet, belirli kernel sürümlerinde düşük yetkili yerel kullanıcının root yetkisine yükselmesine olanak sağlayabiliyor. https://github.com/0xBlackash/CVE-2026-31635

    Post summary

    A public PoC/exploit for CVE‑2026‑31635, a Linux kernel privilege‑escalation bug in the RXRPC/RXGK component, is available on GitHub.

    0402571.1K
    2.4K followersView on X
  • elhacker.NET@elhackernet
    PoC

    Publicado el PoC de DirtyDecrypt para la vulnerabilidad de LPE CVE-2026-31635 en el kernel de Linux https://blog.elhacker.net/2026/05/publicado-el-poc-de-dirtydecrypt-para.html

    Post summary

    A blog post announces the publication of the DirtyDecrypt PoC for the Linux kernel Local Privilege Escalation vulnerability CVE-2026-31635, indicating that proof‑of‑concept code exists.

    01201651.7K
    141.0K followersView on X
  • 嶋田大貴@shimarin
    Disclosure

    これ去年追加されたばかりの機能にまつわるバグで、ほとんどの人はそんな新しいカーネル使ってないので対象外なんだけど、普通の人は対象なのか自分で判断できないので記事にしました。 Linuxカーネル脆弱性 CVE-2026-31635「DirtyDecrypt」は何を確認すべきか https://www.walbrix.co.jp/article/cve-2026-31635-dirtydecrypt.html

    Post summary

    An article was published to explain the Linux kernel CVE‑2026‑31635 (DirtyDecrypt) and how to determine impact, but no proof‑of‑concept, exploit code, or patch information is provided in the text.

    0711042.0K
    4.3K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    PoC

    DirtyDecrypt (CVE-2026-31635) provides a working PoC for a Linux kernel LPE via missing COW guard in rxgk_decrypt_skb, enabling root on RXGK-enabled distributions. https://securityaffairs.com/192436/uncategorized/dirtydecrypt-poc-released-for-yet-another-linux-flaw.html

    Post summary

    The article announces a working proof‑of‑concept that demonstrates a Linux kernel local privilege‑escalation flaw (CVE‑2026‑31635) involving a missing COW guard in rxgk_decrypt_skb, but it does not report active exploitation or a patch.

    040951.4K
    22.5K followersView on X
  • kokumօtօ@__kokumoto
    Exploit

    Linuxの権限昇格脆弱性DirtyDecrypt (CVE-2026-31635)に対応する攻撃コードが公開された。4/25修正。悪用にはカーネルがCONFIG_RXGK構成オプション有効である必要があり、Fedora、Arch Linux、openSUSE Tumbleweed等の上流カーネルリリースに追従するディストロのみで影響。

    Post summary

    A privilege‑escalation exploit for Linux CVE-2026‑31635 has been published, requires CONFIG_RXGK, and a patch was released on April 25; only certain distros following upstream kernels are affected.

    0301132.6K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Linux kernel flaw CVE-2026-31635 (DirtyDecrypt) allows local privilege escalation to root by bypassing Copy-on-Write protections via rxgk_decrypt_skb. https://meterpreter.org/bypassing-the-guardrails-new-dirtydecrypt-linux-flaw-overwrites-root-files-in-memory/ https://t.co/qOjEi1f4oi

    Post summary

    The tweet announces the discovery of a Linux kernel vulnerability (CVE-2026-31635) that enables local privilege escalation by bypassing COW protections, and links to an external article likely containing PoC details.

    030112698
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    【CopyFail亜種】Linuxの権限昇格脆弱性DirtyDecrypt (CVE-2026-31635)について、PoC(攻撃の概念実証コード)が開示された。 https://securityaffairs.com/192436/uncategorized/dirtydecrypt-poc-released-for-yet-another-linux-flaw.html

    Post summary

    PoC for Linux privilege escalation CVE-2026-31635 has been released; no exploit tool, patch, or active attacks reported.

    000821.2K
    7.6K followersView on X
  • Linux Kernel Security@linkersec
    PoC

    DirtyCBC / DirtyDecrypt (CVE-2026-31635?) Write-up: https://github.com/Delphos-Labs/disclosures/tree/main/DirtyCBC Another exploit: https://github.com/v12-security/pocs/tree/main/dirtydecrypt

    Post summary

    The post references a potential CVE‑2026‑31635 and provides links to a write‑up and PoC exploit repositories, indicating a proof of concept is available but with no evidence of active exploitation or patches.

    01062736
    10.4K followersView on X
  • dbugs@ptdbugs
    PoC

    DirtyDecrypt / DirtyCBC CVE: CVE-2026-31635 PT ID: PT-2026-34987 Vendor: Linux Product: Linux CVSS: 7.5 Credits: V12 Description: Linux kernel memory corruption vulnerability in the RxRPC subsystem caused by improper handling of cloned socket buffers ("skb") during packet decryption in "rxgk_decrypt_skb()". The vulnerable code modifies shared packet memory without performing the required copy-on-write validation, allowing crafted RxRPC packets to corrupt kernel memory. Successful exploitation may result in denial of service or potentially privilege escalation depending on the target environment. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-31635 • https://git.kernel.org/stable/c/beee051f259acd286fed64c32c2b31e6f5097eb5 Poc/Exploit: https://github.com/v12-security/pocs/tree/main/dirtydecrypt #dbugs_vuln

    Post summary

    The post announces CVE‑2026‑31635, details a kernel memory corruption flaw, and shares a GitHub-hosted PoC/exploit code.

    010231.2K
    2.6K followersView on X
  • Blue Team News@blueteamsec1
    PoC

    DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability http://dlvr.it/TTxn6T #Linux #CVE202631635 #CyberSecurity #PrivilegeEscalation #Vulnerability https://t.co/y5paCjbtIx

    Post summary

    A proof‑of‑concept for the Linux kernel LPE vulnerability CVE‑2026‑31635 has been released and linked; no evidence of active exploitation or patch information is provided.

    020211.9K
    57.5K followersView on X
  • AI Heartland@peaks2314
    PoC

    🚨 Linux カーネルに LPE 脆弱性(CVE-2026-31635) ▼何が起きた DirtyDecrypt(別名 DirtyCBC)と呼ばれるカーネルの権限昇格バグに PoC が公開された。CVSS 7.5。2026年5月9日に報告され、すでにパッチ提供済み。 ▼影響 ローカルユーザーが root 権限を取得できる。パッチ適用前のカーネルが対象。 ▼対応 各ディストリビューションのセキュリティアドバイザリを確認し、最新カーネルへアップデートする。 🔗 https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html #Linux

    Post summary

    A Proof‑of‑Concept for CVE-2026-31635, a local privilege escalation flaw in the Linux kernel, has been released with CVSS 7.5, and a patch is already available; users should update to the latest kernel.

    00050122
    3.4K followersView on X
  • Misbar | مسبار@MisbarSec
    PoC

    📌 تم إصدار (PoC) لـ ثغرة CVE-2026-31635 المعروفة بـ DirtyDecrypt تم اكتشاف ثغرة أمنية في نواة لينكس تسمح برفع الامتيازات المحلية (LPE) وتم الإبلاغ عنها من قبل فريق Zellic و V12. تم تصنيفها بـ DirtyDecrypt (أو DirtyCBC). تم إصدار برهان على قابلية الاستغلال (PoC) للثغرة التي تم إصلاحها مؤخرًا. 🔗 للمزيد: https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html

    Post summary

    A PoC for the locally‑exploitable Linux kernel flaw CVE-2026-31635, known as DirtyDecrypt, has been released, with a link to the proof of concept, but no active exploitation or patch details are provided.

    00031996
    299 followersView on X
  • AI Security Gateway@AISGateway
    PoC

    DirtyDecrypt (CVE-2026-31635) is a Linux kernel LPE vuln with a live PoC drop. Kernel exploits and AI deployments intersect more than most teams realize. If your LLM inference server is compromised, prompt logs, API keys, and PII in transit are all exposed. Here's the governance chain: Attacker escalates privileges on your AI server → reads unredacted prompt logs → harvests PII, credentials, internal context that was never supposed to leave your stack. The kernel vuln is the entry point. Unguarded LLM traffic is the payload.🧵

    Post summary

    A new Linux kernel privilege‑escalation vulnerability (CVE‑2026‑31635) called DirtyDecrypt is disclosed with a live PoC, highlighting risks for AI inference servers via exposed log and credential data.

    21010120
    39 followersView on X
  • DFIR Radar@DFIR_Radar
    General

    Elastic Security Labs maps a durable, outcome-oriented Linux LPE detection framework against 11 public 2026 PoCs, covering page-cache corruption, namespace abuse, trusted-helper theft, and SUID misconfiguration without relying on per-CVE rules. Key findings: - Seven of 13 tracked 2026 Linux LPEs share a copy-on-write page-cache corruption primitive: Copy Fail (CVE-2026-31431), DirtyFrag (CVE-2026-43284/43500), Fragnesia (CVE-2026-46300), DirtyDecrypt (CVE-2026-31635), pedit COW (CVE-2026-46331), DirtyClone (CVE-2026-43503), and RefluXFS. The kernel trigger varies across AF_ALG, ESP/RxRPC, act_pedit, and skb helpers, but every exploit still ends the same way: a SUID helper or interpreter runs with effective uid 0. Qualys and others used LLM-assisted workflows to discover several of these, accelerating the per-bug-class pace. - The framework detects in two layers. Layer one is outcome-oriented: exec from a writable path (/tmp, /dev/shm, /var/tmp, /home, /run/user) followed by a uid_change to 0, correlated by parent entity ID within a short window. Layer two adds per-class signals: AF_ALG socket bursts plus splice for Copy Fail; unshare(CLONE_NEWUSER) preceding a root transition for CIFSwitch (CVE-2026-46243) and OVSwrap (CVE-2026-64531); busctl --system calls for ptrace_may_dream; and shadow-read alerts for chage_pwn (CVE-2026-46333). - CVE-2026-46333 (exit-time FD theft via pidfd_getfd) is worth special attention. #DFIR_Radar

    Post summary

    Elastic Security Labs presented a detection framework for Linux LPEs, referencing 11 public 2026 PoCs and detailing technical mechanisms such as page‑cache corruption and namespace abuses; no exploit code, patch, or active exploitation claims are made.

    20100268
    1.9K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.16--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more