---
schema: 1
kind: vulnerability
title: "CVE-2026-31635 (\"DirtyDecrypt\") — Linux kernel RxGK page-cache write, public PoC; Fedora, Arch, openSUSE Tumbleweed affected"
headline: "CVE-2026-31635 (\"DirtyDecrypt\") — Linux kernel RxGK page-cache write, public PoC; Fedora, Arch, openSUSE Tumbleweed affected"
summary: CVE-2026-31635 is a page-cache write due to a missing copy-on-write guard in rxgk_decrypt_skb() in net/rxrpc/rxgk_crypt.c — the RxGK (Kerberos-for-AFS) subsystem of the Linux kernel.
discovered_at: "2026-05-20T05:00:08Z"
event_date: null
run_id: 2026-05-20-a0f7b07f
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - priv-esc
  - poc-public
  - patch-available
regions:
  - global
sectors:
  - education
  - technology
entities: []
cves:
  - id: CVE-2026-31635
    cvss: "7.5"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://www.bleepingcomputer.com/news/security/exploit-available-for-new-dirtydecrypt-linux-root-escalation-flaw/"
    publisher: "BleepingComputer, 2026-05-19"
    role: primary
  - url: "https://moselwal.com/blog/dirtydecrypt-linux-kernel-rxgk-cve-2026-31635"
    publisher: "Moselwal technical analysis, 2026-05-18"
    role: corroborating
  - url: "https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html"
    publisher: "The Hacker News, 2026-05-19"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**For Fedora / Arch / openSUSE Tumbleweed Linux fleet, apply the kernel patch from 2026-04-25 or later (DirtyDecrypt / CVE-2026-31635).** Confirm with `grep RXGK /boot/config-$(uname -r)`. Public PoC released 2026-05-19 ([BleepingComputer, 2026-05-19](https://www.bleepingcomputer.com/news/security/exploit-available-for-new-dirtydecrypt-linux-root-escalation-flaw/))."
migrated_from: briefs/2026-05-20.md
---

CVE-2026-31635 is a **page-cache write due to a missing copy-on-write guard in `rxgk_decrypt_skb()` in `net/rxrpc/rxgk_crypt.c`** — the RxGK (Kerberos-for-AFS) subsystem of the Linux kernel. Researchers at Zellic/V12 disclosed the issue on 2026-05-09; kernel maintainers traced the regression and noted it was a duplicate of a vulnerability quietly patched in mainline on 2026-04-25. A **working PoC was published by V12 on 2026-05-19**, prompting [BleepingComputer](https://www.bleepingcomputer.com/news/security/exploit-available-for-new-dirtydecrypt-linux-root-escalation-flaw/) and [The Hacker News](https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html) coverage (Hacker News carries the CVSS 7.5 score; the [Moselwal technical write-up](https://moselwal.com/blog/dirtydecrypt-linux-kernel-rxgk-cve-2026-31635) characterises the LPE class as in the 7.8–8.1 range without a settled NVD score at time of publication). Affected only where kernels are compiled with `CONFIG_RXGK=y` — that's **Fedora, Arch Linux, and openSUSE Tumbleweed** in standard configurations. Debian Stable, RHEL, and Ubuntu LTS build kernels without `CONFIG_RXGK` and are not affected. No in-the-wild exploitation reported.

DirtyDecrypt is assessed as a variant of the "Copy Fail" family (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-46300). Mitigation: apply the kernel patch from 2026-04-25 (or any linux-stable build derived from it); or temporarily blacklist the `rxrpc` module via `/etc/modprobe.d/` — the latter breaks IPsec/AFS-VPN and is fragile. Verify with `grep RXGK /boot/config-$(uname -r)`. Detection: Falco / Tetragon rules on unexpected `rxrpc` module load events; Sysmon-for-Linux EID 8 for UID changes from unprivileged processes; container runtime alerts for unexpected root spawning from container context. Relevant where rolling-release Linux distros host CI/CD runners, developer workstations, or research VMs in EU/CH public-sector environments.
