UBUNTU-CVE-2026-31431

Advisory lineage Upstream: 1 Downstream: 34
Published: 22 Apr 2026, 09:16
Last modified:17 Jul 2026, 23:38

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
3.1 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Apr 2026, 09:16
Published
Vulnerability first disclosed
17 Jul 2026, 23:38
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Systems

  • ubuntulinux

    all | all | all | all | < 4.15.0-250.262 | < 5.4.0-230.250 | < 5.15.0-179.189 | < 6.8.0-117.117 | < 6.17.0-29.29

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | all | all | all | < 4.15.0-1192.205 | < 5.4.0-1159.169 | < 5.15.0-1108.115 | < 6.8.0-1055.58 | < 6.17.0-1015.15

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all | < 5.15.0-1108.115~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all | < 5.4.0-1160.170~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    all | < 6.17.0-1017.17~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    all | < 6.8.0-1057.60~22.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2130.136 | all | < 5.4.0-1159.169+fips1 | < 5.15.0-1108.115+fips1 | < 6.8.0-1055.58+fips1

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | all | all | < 4.15.0-1201.216~14.04.1 | all | < 5.4.0-1163.169 | < 5.15.0-1114.123 | < 6.8.0-1056.62 | < 6.17.0-1015.15

  • ubuntulinux-azure-4.15

    all | < 4.15.0-1201.216

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all | < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    all | < 5.4.0-1163.169~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    all

  • ubuntulinux-azure-6.17

    all | < 6.17.0-1015.15~24.04.1

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    all | < 6.8.0-1059.65~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.14

    all

  • ubuntulinux-azure-fde-6.17

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2110.116 | all | < 5.4.0-1163.169+fips1 | < 5.15.0-1114.123+fips1 | < 6.8.0-1059.65+fips1

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-azure-nvidia-6.14

    all

  • ubuntulinux-bluefield

    all | < 5.4.0-1118.125 | < 5.15.0-1092.94 | all

  • ubuntulinux-fips

    < 4.15.0-1147.159 | all | < 5.4.0-1133.143 | < 5.15.0-179.189+fips1 | < 6.8.0-124.124+fips1

  • ubuntulinux-gcp

    all | all | all | all | all | < 5.4.0-1162.171 | < 5.15.0-1108.117 | < 6.8.0-1058.61 | < 6.17.0-1018.19

  • ubuntulinux-gcp-4.15

    all | < 4.15.0-1185.202

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    all | < 5.15.0-1108.117~20.04.1

Showing first 50 affected entries in server-rendered view.

References (38)