Vulnerabilities

CVE-2026-31431

Actively exploited (CISA KEV) High 7.8 CVSS 3.1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Description as published by the source, in English.

Key facts

Published
2026-04-22
Last modified
2026-09-08
Assigned by
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Scored by
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Probability of exploitation
94.5 % among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Yes, see references

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-01, with a remediation deadline of 2026-05-15 for US federal agencies.

Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Amazon Amazon Linux all versions listed Affected
Arista Cloudvision Agni ≥ 2024.4.0, ≤ 2025.2.2 Affected
Arista Cloudvision Portal ≥ 2024.2.0, ≤ 2026.1.0 Affected
Arista Netvisor Os < 7.1.0 Affected
Arista Netvisor Os 7.1.0 Affected
Arista Velocloud Edge ≥ 4.5.0, ≤ 6.4.1 Affected
Arista Velocloud Gateway all versions listed Affected
Arista Velocloud Orchestrator all versions listed Affected
Canonical Ubuntu Linux all versions listed Affected
Canonical Ubuntu Linux 14.04 Affected
Canonical Ubuntu Linux 16.04 Affected
Canonical Ubuntu Linux 18.04 Affected
Canonical Ubuntu Linux 20.04 Affected
Canonical Ubuntu Linux 22.04 Affected
Canonical Ubuntu Linux 24.04 Affected
Canonical Ubuntu Linux 25.10 Affected
Debian Debian Linux 11.0 Affected
Debian Debian Linux 12.0 Affected
Debian Debian Linux 13.0 Affected
Linux Linux Kernel 7.0 Affected
Linux Linux Kernel ≥ 4.14, < 5.10.254 Affected
Linux Linux Kernel ≥ 5.11, < 5.15.204 Affected
Linux Linux Kernel ≥ 5.16, < 6.1.170 Affected
Linux Linux Kernel ≥ 6.13, < 6.18.22 Affected
Linux Linux Kernel ≥ 6.19, < 6.19.12 Affected
Linux Linux Kernel ≥ 6.2, < 6.6.137 Affected
Linux Linux Kernel ≥ 6.7, < 6.12.85 Affected
Nixos Nixos < 25.11 Affected
Opensuse Leap 15.3 Affected
Opensuse Leap 15.4 Affected
Opensuse Leap 15.5 Affected
Opensuse Leap 15.6 Affected
Redhat Enterprise Linux 10.0 Affected
Redhat Enterprise Linux 8.0 Affected
Redhat Enterprise Linux 9.0 Affected
Redhat Enterprise Linux Aus 8.4 Affected
Redhat Enterprise Linux Aus 8.6 Affected
Redhat Enterprise Linux Eus 10.0 Affected
Redhat Enterprise Linux Eus 8.4 Affected
Redhat Enterprise Linux Eus 9.4 Affected
Redhat Enterprise Linux Eus 9.6 Affected
Redhat Enterprise Linux Tus 8.6 Affected
Redhat Enterprise Linux Tus 8.8 Affected
Redhat Enterprise Linux Update Services For Sap Solutions 8.6 Affected
Redhat Enterprise Linux Update Services For Sap Solutions 8.8 Affected
Redhat Enterprise Linux Update Services For Sap Solutions 9.0 Affected
Redhat Enterprise Linux Update Services For Sap Solutions 9.2 Affected
Redhat Openshift Container Platform 4.0 Affected
Redhat Openshift Container Platform ≥ 4.12, < 4.12.89 Affected
Redhat Openshift Container Platform ≥ 4.13, < 4.13.66 Affected
Redhat Openshift Container Platform ≥ 4.14, < 4.14.65 Affected
Redhat Openshift Container Platform ≥ 4.15, < 4.15.64 Affected
Redhat Openshift Container Platform ≥ 4.16, < 4.16.61 Affected
Redhat Openshift Container Platform ≥ 4.17, < 4.17.53 Affected
Redhat Openshift Container Platform ≥ 4.18, < 4.18.40 Affected
Redhat Openshift Container Platform ≥ 4.19, < 4.19.30 Affected
Redhat Openshift Container Platform ≥ 4.20, < 4.20.21 Affected
Redhat Openshift Container Platform ≥ 4.21, < 4.21.14 Affected
Siemens Simatic Ax Runtime all versions listed Affected
Siemens Simatic Cn 4100 all versions listed Not affected

Weakness type

References

Related at Berigo

Articles

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities