- Description
- In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the packet and is supposed to verify that it fits in the remaining bytes. The existing check is inverted, so oversized RESPONSE authenticators are accepted and passed to rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an impossible length and hit BUG_ON(len). Decoded from the original latest-net reproduction logs with scripts/decode_stacktrace.sh: RIP: __skb_to_sgvec() [net/core/skbuff.c:5285 (discriminator 1)] Call Trace: skb_to_sgvec() [net/core/skbuff.c:5305] rxgk_decrypt_skb() [net/rxrpc/rxgk_common.h:81] rxgk_verify_response() [net/rxrpc/rxgk.c:1268] rxrpc_process_connection() [net/rxrpc/conn_event.c:266 net/rxrpc/conn_event.c:364 net/rxrpc/conn_event.c:386] process_one_work() [kernel/workqueue.c:3281] worker_thread() [kernel/workqueue.c:3353 kernel/workqueue.c:3440] kthread() [kernel/kthread.c:436] ret_from_fork() [arch/x86/kernel/process.c:164] Reject authenticator lengths that exceed the remaining packet payload.
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- NVD status
- Modified
- Products
- linux_kernel
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- nvd@nist.gov
- NVD-CWE-noinfo
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-130
- Hype score
- Not currently trending
23:13 UTC: CVE-2026-31635 disclosed. 🚨 Public PoC exploit code has been released for DirtyDecrypt, a now-patched Linux kernel vulnerability tracked as CVE
@lyrie_ai
7 Jun 2026
424 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-31635: 🚨 Public PoC exploit code is out for DirtyDecrypt, a patched Linux kernel flaw linked to CVE-2026-31635 that could allow local privilege escalation. It affects CONFIGRXGK-enabled systems, including Fedora, Arch Linux, and openSUSE Tumbleweed. Details:…
@lyrie_ai
6 Jun 2026
790 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Linux Kernel の脆弱性 DirtyDecrypt CVE-2026-31635 が FIX:root 権限昇格と PoC の提供 https://t.co/feNqRWnEuE Linux カーネルで発見された脆弱性 CVE-2026-31635 は、データを復号する際のメモリ管理の問題に起因します。
@iototsecnews
26 May 2026
104 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-49113 2 - CVE-2026-26980 3 - CVE-2026-31635 4 - CVE-2026-34908 5 - CVE-2026-42897 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
25 May 2026
154 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 LINUX: DirtyDecrypt (CVE-2026-31635) PoC público → escalada a ROOT 🔓 Vulnerabilidad en rxrpc (RxGK). Afecta Debian 13 y otras distros ⚠️ Cuarta LPE en 3 semanas de la familia Copy Fail. #Linux #LPE #CVE #DirtyDecrypt #Seguridad https://t.co/atZvhFg1GJ
@esecintelcl
19 May 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 LINUX: DirtyDecrypt (CVE-2026-31635) PoC público → escalada a ROOT 🔓 Variante de Copy Fail. Afecta distribuciones con CONFIG_RXGK (Fedora, Arch, openSUSE) ⚠️ Parche disponible hace semanas. Actualizar (para evitar explotación) #Linux #LPE #CVE #Seguridad https:
@esecintelcl
19 May 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DirtyDecrypt / DirtyCBC CVE: CVE-2026-31635 PT ID: PT-2026-34987 Vendor: Linux Product: Linux CVSS: 7.5 Credits: V12 Description: Linux kernel memory corruption vulnerability in the RxRPC subsystem caused by improper handling of cloned socket buffers ("skb") during packet
@ptdbugs
19 May 2026
151 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
DirtyDecrypt: Linux-Kernel-LPE im RxGK-Subsystem (CVE-2026-31635) mit öffentlichem PoC https://t.co/VhXjmacIJ9 https://t.co/6tqMTkfe4O
@moselwal
19 May 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fragnesia (CVE-2026-46300) i DirtyDecrypt (CVE-2026-31635) ( https://t.co/uQUeNj3UlE ) #linux #kernel #security https://t.co/9cg1KcRJw0
@nfsec_pl
18 May 2026
120 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
NEW THREAT INTEL: DirtyDecrypt (CVE-2026-31635) Linux kernel rxgk root LPE w/ public PoC. 9 detections, 16 IOCs. https://t.co/InZPiJEwIL #ThreatIntel #Linux #LPE #CVE https://t.co/dBah0JXPgg
@threadlinqs
18 May 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EAE31F43-AAC5-4801-B2B2-119D62A532A2",
"versionEndExcluding": "6.18.23",
"versionStartIncluding": "6.16.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1490EF9B-9080-481C-8D22-1306AAE664E4",
"versionEndExcluding": "6.19.13",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:-:*:*:*:*:*:*",
"matchCriteriaId": "6238B17D-C12B-458F-A138-97039BFC4595",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
"matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
"matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*",
"matchCriteriaId": "58A9FEFF-C040-420D-8F0A-BFDAAA1DF258",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*",
"matchCriteriaId": "1D2315C0-D46F-4F85-9754-F9E5E11374A6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*",
"matchCriteriaId": "512EE3A8-A590-4501-9A94-5D4B268D6138",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]