INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

DirtyDecrypt Linux Root Exploit Vulnerability

| 2026-05-20 07:36 CRITICAL MEDIUM
Executive Summary AI-generated
The recent discovery of DirtyDecrypt, a local privilege escalation vulnerability in the kernel, has sent shockwaves through the cybersecurity community. This exploit, which was first reported on April 29 by researchers at Theori, is particularly concerning as it can be used to gain access to sensitive data and systems within containerized environments. With multiple vulnerabilities already identified, including Copy Fail, DirtyDecrypt poses a significant threat to Linux-based infrastructure. As more details emerge about this attack, the potential consequences for organizations relying on these systems become increasingly clear.
Technical Mitigations AI-generated
* Implement COW (Copy-On-Write) guards: Ensure that shared memory pages are protected by a copy-on-write mechanism, preventing writes to shared pages from bleeding into other processes' data. * Use secure socket buffer decryption mechanisms: Implement secure and robust socket buffer decryption mechanisms, such as those provided by the `rxgk_decrypt_skb()` function in the Linux kernel, to prevent local privilege escalation vulnerabilities like DirtyDecrypt. * Regularly update and patch operating systems: Keep all operating systems, including Linux distributions, up-to-date with the latest security patches and updates to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Implement secure coding practices in development environments: Ensure that developers follow best practices for secure coding, such as using secure socket buffer decryption mechanisms, validating input data, and implementing access controls to prevent unauthorized access to sensitive resources.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-31431CVE-2026-31431 CVE-2026-43500CVE-2026-43500 CVE-2026-46333CVE-2026-46333 CVE-2026-43284CVE-2026-43284 CVE-2026-31635CVE-2026-31635 CVE-2026-41651CVE-2026-41651 CVE-2026-46300CVE-2026-46300
Target & Sectors
Global Scope
Incident Timeline
‎April 25
Tharros patched CVE-2026-31635 on April 25.
vulnerability CVE-2026-31635
organisation Tharros
‎April 29
Threat actors exploited a local privilege escalation vulnerability in the AF_ALG cryptographic socket interface to target researchers at Theori.
tactic Privilege Escalation
organisation CVE-2026-31431
organisation Copy Fail
organisation Theori
‎April 29, 2026
Threat actors exploited a local privilege escalation flaw in the AF_ALG cryptographic socket interface to gain unauthorized access.
tactic Privilege Escalation
‎May 1
Threat actors used a previously undisclosed Linux flaw to target the Cybersecurity and Infrastructure Security Agency (CISA) on May 1.
infrastructure Linux
‎May 5
The researcher who published details of the CVE-2026-43284 flaw was forced to disclose it publicly due to a premature merge into the public tree on May 5.
vulnerability CVE-2026-43284
‎May 9, 2026
The vulnerability, dubbed DirtyDecrypt or DirtyCBC, was discovered and reported by the Zellic and V12 security team on May 9, 2026.
organisation V12
organisation Kubernetes
organisation PackageKit
infrastructure Linux
organisation CONFIG_RXGK
organisation Fedora
organisation AlmaLinux
organisation Amazon
organisation CloudLinux
organisation SecurityAffairs
organisation CVE
organisation DirtyDecrypt PoC
organisation CVE-2026
organisation CVE-2026-46300
organisation Fragnesia
organisation SSH
organisation DirtyCBC
organisation CopyFail / DirtyFrag / Fragnesia
organisation Moselwal
‎May 15
Threat actors used a previously disclosed Linux flaw to target the Cybersecurity and Infrastructure Security Agency (CISA).
infrastructure Linux
‎2026/05/20
Linux kernel vulnerability allows local attackers to gain root access.
infrastructure Linux
organisation PoC
organisation LPE
organisation rxgk module
organisation PackageKit
organisation CVE-2026-31431
organisation Copy Fail
organisation CVE-2026
organisation CVE-2026-46300
organisation Fragnesia
organisation Zellic
organisation Copy Fail 2
organisation Dirty Frag
organisation IPsec
organisation SSH
organisation CVSS
organisation PoC Released
organisation DirtyDecrypt
organisation DirtyDecrypt PoC Released
organisation CONFIG_RXGK
organisation Rocky Linux Debuts Security Repository
organisation DirtyDecrypt Linux
organisation RxGK
organisation the Andrew File System
organisation CVE
organisation the NIST National Vulnerability Database
organisation NVD
organisation the DirtyDecrypt PoC
organisation COW
organisation cts
organisation V12
organisation DirtyCBC
organisation CPU
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources