<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[There&#x27;s apparently another Linux LPE]]></title><description><![CDATA[<p>There's apparently another Linux LPE.<br /><a href="https://github.com/v12-security/pocs/tree/main/dirtydecrypt" rel="nofollow noopener">DirtyDecrypt, also known as DirtyCBC, is a variant of CopyFail / DirtyFrag / Fragnesia</a>.<br />I suspect it may be <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31635" rel="nofollow noopener">CVE-2026-31635</a>.</p><p>I have not been able to get it to actually work on <strong>any</strong> Linux distro that I've tried.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/179/745/500/494/original/6c5a2fe6d5962819.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/180/957/041/409/original/0c5bb5c781eafe37.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/181/761/735/842/original/c5a4f745e4856d1a.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/182/778/094/262/original/e84f69c94cea9a1c.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/4d78f9a7-83ce-4ab8-98ed-6f3b27d1a182/there-s-apparently-another-linux-lpe</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 17:39:08 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4d78f9a7-83ce-4ab8-98ed-6f3b27d1a182.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 17 May 2026 13:36:57 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to There&#x27;s apparently another Linux LPE on Sun, 17 May 2026 20:42:37 GMT]]></title><description><![CDATA[<p>Also, the Dirty frag mitigation protects against this variant as well:</p><pre><code>sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' &gt; /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2&gt;/dev/null; echo 3 &gt; /proc/sys/vm/drop_caches; true"<br /></code></pre>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/591/855/829/741/767/original/68f88f0c2b013dfd.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116591857330104400</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116591857330104400</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Sun, 17 May 2026 20:42:37 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s apparently another Linux LPE on Sun, 17 May 2026 18:45:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> And there I was, hoping for a relaxed week <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f629.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--weary" style="height:23px;width:auto;vertical-align:middle" title="😩" alt="😩" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.online/users/studiolo_rb/statuses/116591398487459299</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.online/users/studiolo_rb/statuses/116591398487459299</guid><dc:creator><![CDATA[studiolo_rb@mastodon.online]]></dc:creator><pubDate>Sun, 17 May 2026 18:45:56 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s apparently another Linux LPE on Sun, 17 May 2026 16:29:01 GMT]]></title><description><![CDATA[<p>Apparently <a href="https://infosec.exchange/@decio/116590741505627020">exploitation requires <code>CONFIG_RXGK</code>, which most distros don't ship</a></p><p>Except for Fedora.<br />Or another distro that is running the mainline Linux kernel.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/856/707/771/729/original/6e1dbeab3707737e.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/857/065/472/791/original/cc05d79318c4ef0c.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116590860115662310</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116590860115662310</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Sun, 17 May 2026 16:29:01 GMT</pubDate></item><item><title><![CDATA[Reply to There&#x27;s apparently another Linux LPE on Sun, 17 May 2026 15:58:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span>   Confirmed same experience on recent distros.</p><p>Apparently the trick is it needs CONFIG_RXGK compiled in, which most distros don't ship. <br />Kernel 6.8 on Ubuntu 24.04? Nothing.</p><p>But on mainline kernel 7.0.0 it works (slow but solid):<br />96/96 bytes <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2705.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--white_check_mark" style="height:23px;width:auto;vertical-align:middle" title="✅" alt="✅" /> whoami → root <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f389.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--tada" style="height:23px;width:auto;vertical-align:middle" title="🎉" alt="🎉" /></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/726/493/720/536/original/d54723ee584b19a3.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/590/727/586/769/376/original/cc53057111d3fe71.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/decio/statuses/116590741505627020</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/decio/statuses/116590741505627020</guid><dc:creator><![CDATA[decio@infosec.exchange]]></dc:creator><pubDate>Sun, 17 May 2026 15:58:51 GMT</pubDate></item></channel></rss>