CVE-2026-31431

Aliases:RHSA-2026:15976UBUNTU-CVE-2026-31431DEBIAN-CVE-2026-31431RHSA-2026:14926RHSA-2026:15978RHSA-2026:16018RHSA-2026:16063RHSA-2026:16111RHSA-2026:16208RHSA-2026:16209RHSA-2026:16210CGA-264j-7mjh-g6fgCGA-45p5-32r4-wpc5CGA-777j-9359-v4fmCGA-c34j-wrf8-jmhxCGA-cfvm-96rm-h9cxCGA-mv3m-43pf-mm3cCGA-v6f9-5h8w-hf7mopenSUSE-SU-2026:11765-1
Advisory lineage Upstream: 0 Downstream: 83
Analyzed
Published: 22 Apr 2026, 08:15
Last modified:08 Sept 2026, 08:47

Vulnerability Summary

Overall Risk (default)
high
61/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
99.91% CRITICAL
100% probability +3.64%
KEV
Listed
CIRCL • CISA
2 listings
Ransomware
No reports
Public exploits
9 found
Dark Web
Not detected

Timeline

22 Apr 2026, 08:15
Published
Vulnerability first disclosed
01 May 2026, 00:00
Added to CISA KEV
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
02 May 2026, 00:00
Added to CIRCL KEV
Added to Known Exploited Vulnerabilities catalog
15 May 2026, 00:00
CISA Remediation Due
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
08 Sept 2026, 08:47
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 99.91% Percentile: 100%

Techniques & Countermeasures

  • CWE-669Incorrect Resource Transfer Between Spheres

    The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

  • CWE-1288Improper Validation of Consistency within Input

    The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.

Affected Systems

  • amazonamazon_linux

    na

  • chainguardlinux-aws-6.12

    < 6.12.83-r2

  • chainguardlinux-azure-6.12

    < 6.12.83-r2

  • chainguardlinux-gcp-6.12

    < 6.12.83-r2

  • chainguardlinux-qemu-6.12

    < 6.12.85-r0

  • chainguardlinux-vmware-6.12

    < 6.12.85-r0

  • aristacloudvision_agni

    ≥ 2024.4.0, ≤ 2025.2.2

  • aristacloudvision_portal

    ≥ 2024.2.0, ≤ 2026.1.0

  • aristanetvisor_os

    < 7.1.0 | 7.1.0 | 7.1.0:hotfix7

  • aristavelocloud_edge

    ≥ 4.5.0, ≤ 6.4.1

  • aristavelocloud_gateway

    na

  • aristavelocloud_orchestrator

    na

  • canonicalubuntu_linux

    na | 14.04 | 16.04 | 18.04 | 20.04 | 22.04 | 24.04 | 25.10

  • debianlinux

    < 5.10.251-3 | < 6.1.170-1 | < 6.12.85-1 | < 6.19.12-1

  • debianlinux-6.1

    < 6.1.170-1~deb11u1

  • ubuntulinux

    < 4.15.0-250.262 | < 5.4.0-230.250 | < 5.15.0-179.189 | < 6.8.0-117.117 | < 6.17.0-29.29

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    < 4.15.0-1192.205 | < 5.4.0-1159.169 | < 5.15.0-1108.115 | < 6.8.0-1055.58 | < 6.17.0-1015.15

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1108.115~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1160.170~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    < 6.17.0-1017.17~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1057.60~22.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2130.136 | all | < 5.4.0-1159.169+fips1 | < 5.15.0-1108.115+fips1 | < 6.8.0-1055.58+fips1

  • ubuntulinux-aws-hwe

    < 4.15.0-1192.205~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1201.216~14.04.1 | all | < 5.4.0-1163.169 | < 5.15.0-1114.123 | < 6.8.0-1056.62 | < 6.17.0-1015.15

  • ubuntulinux-azure-4.15

    < 4.15.0-1201.216

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1163.169~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    all

  • ubuntulinux-azure-6.17

    < 6.17.0-1015.15~24.04.1

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1059.65~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

Showing first 50 affected entries in server-rendered view.

References (191)