The public exploit for DirtyDecrypt raises the urgency for Linux administrators because this is no longer just a theoretical kernel flaw. The vulnerability is a local privilege escalation issue in the Linux kernel’s rxgk module, and the available proof-of-concept can allow attackers with local access to gain root privileges on affected systems. That makes it especially dangerous when combined with stolen credentials, vulnerable web applications, compromised containers, or any initial foothold that gives an attacker limited shell access.

Organizations should immediately apply the latest kernel updates, verify whether vulnerable modules are present or loaded, and use documented mitigations where patching cannot be done quickly. Security teams should also monitor for suspicious privilege escalation activity, unexpected module usage, abnormal shell behavior, and post-exploitation attempts. Local privilege escalation bugs are often dismissed as “not remote,” which is comforting in the same way locking only the front gate is comforting while the side door is open. Once attackers land on a Linux host, root access is often the difference between an incident and a full compromise.


A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. [...]

Source: Exploit available for new DirtyDecrypt Linux root escalation flaw via Bleeping Computer — published 18 May 2026.