PoC Turns rxgk-Only Linux Bug Into Root Risk

This is not a general Linux root bug. Exposure depends on kernels built with CONFIG_RXGK, so the real risk sits in a narrow set of distro-specific builds, not most Linux systems. A proof-of-concept is now public for DirtyDecrypt, also called DirtyCBC, aligning with CVE-2026-31635, which was patched in mainline on April 25. The flaw is a local privilege escalation in the rxgk module, and successful exploitation on affected builds can give an attacker root. The forward risk is practical exploitation on any host that actually ships the rxgk path, especially in fast-moving distros and AFS-related deployments. Standard kernel patch checks can miss exposure if they do not account for build configuration.

Part of the PlainSec briefing for 2026-05-19

Sources