Sårbarheter

CVE-2026-31431

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Utnyttes aktivt (CISA KEV) Høy 7.8 CVSS 3.1

Beskrivelse

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Beskrivelsen gjengis slik kilden har publisert den, på engelsk.

Nøkkelfakta

Publisert
2026-04-22
Sist endret
2026-09-08
Tildelt av
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS-vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Scoret av
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sannsynlighet for utnyttelse
94.5 % blant de aller høyeste av alle kjente sårbarheter
EPSS, neste 30 dager, modell v2026.06.15
Rettelse finnes
Ja, se referansene

Aktivt utnyttet

CISA førte denne sårbarheten inn i katalogen over kjente utnyttede sårbarheter 2026-05-01, med utbedringsfrist 2026-05-15 for amerikanske føderale etater.

Pålagt tiltak: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Berørte produkter

Leverandør Produkt Versjoner Status
Amazon Amazon Linux alle oppførte versjoner Berørt
Arista Cloudvision Agni ≥ 2024.4.0, ≤ 2025.2.2 Berørt
Arista Cloudvision Portal ≥ 2024.2.0, ≤ 2026.1.0 Berørt
Arista Netvisor Os < 7.1.0 Berørt
Arista Netvisor Os 7.1.0 Berørt
Arista Velocloud Edge ≥ 4.5.0, ≤ 6.4.1 Berørt
Arista Velocloud Gateway alle oppførte versjoner Berørt
Arista Velocloud Orchestrator alle oppførte versjoner Berørt
Canonical Ubuntu Linux alle oppførte versjoner Berørt
Canonical Ubuntu Linux 14.04 Berørt
Canonical Ubuntu Linux 16.04 Berørt
Canonical Ubuntu Linux 18.04 Berørt
Canonical Ubuntu Linux 20.04 Berørt
Canonical Ubuntu Linux 22.04 Berørt
Canonical Ubuntu Linux 24.04 Berørt
Canonical Ubuntu Linux 25.10 Berørt
Debian Debian Linux 11.0 Berørt
Debian Debian Linux 12.0 Berørt
Debian Debian Linux 13.0 Berørt
Linux Linux Kernel 7.0 Berørt
Linux Linux Kernel ≥ 4.14, < 5.10.254 Berørt
Linux Linux Kernel ≥ 5.11, < 5.15.204 Berørt
Linux Linux Kernel ≥ 5.16, < 6.1.170 Berørt
Linux Linux Kernel ≥ 6.13, < 6.18.22 Berørt
Linux Linux Kernel ≥ 6.19, < 6.19.12 Berørt
Linux Linux Kernel ≥ 6.2, < 6.6.137 Berørt
Linux Linux Kernel ≥ 6.7, < 6.12.85 Berørt
Nixos Nixos < 25.11 Berørt
Opensuse Leap 15.3 Berørt
Opensuse Leap 15.4 Berørt
Opensuse Leap 15.5 Berørt
Opensuse Leap 15.6 Berørt
Redhat Enterprise Linux 10.0 Berørt
Redhat Enterprise Linux 8.0 Berørt
Redhat Enterprise Linux 9.0 Berørt
Redhat Enterprise Linux Aus 8.4 Berørt
Redhat Enterprise Linux Aus 8.6 Berørt
Redhat Enterprise Linux Eus 10.0 Berørt
Redhat Enterprise Linux Eus 8.4 Berørt
Redhat Enterprise Linux Eus 9.4 Berørt
Redhat Enterprise Linux Eus 9.6 Berørt
Redhat Enterprise Linux Tus 8.6 Berørt
Redhat Enterprise Linux Tus 8.8 Berørt
Redhat Enterprise Linux Update Services For Sap Solutions 8.6 Berørt
Redhat Enterprise Linux Update Services For Sap Solutions 8.8 Berørt
Redhat Enterprise Linux Update Services For Sap Solutions 9.0 Berørt
Redhat Enterprise Linux Update Services For Sap Solutions 9.2 Berørt
Redhat Openshift Container Platform 4.0 Berørt
Redhat Openshift Container Platform ≥ 4.12, < 4.12.89 Berørt
Redhat Openshift Container Platform ≥ 4.13, < 4.13.66 Berørt
Redhat Openshift Container Platform ≥ 4.14, < 4.14.65 Berørt
Redhat Openshift Container Platform ≥ 4.15, < 4.15.64 Berørt
Redhat Openshift Container Platform ≥ 4.16, < 4.16.61 Berørt
Redhat Openshift Container Platform ≥ 4.17, < 4.17.53 Berørt
Redhat Openshift Container Platform ≥ 4.18, < 4.18.40 Berørt
Redhat Openshift Container Platform ≥ 4.19, < 4.19.30 Berørt
Redhat Openshift Container Platform ≥ 4.20, < 4.20.21 Berørt
Redhat Openshift Container Platform ≥ 4.21, < 4.21.14 Berørt
Siemens Simatic Ax Runtime alle oppførte versjoner Berørt
Siemens Simatic Cn 4100 alle oppførte versjoner Ikke berørt

Svakhetstype

Referanser

Relatert hos Berigo

Artikler

Berører dette dere?

En sårbarhet betyr bare noe hvis dere kjører produktet, i en berørt versjon, et sted en angriper kommer til.

Sjekk aktivalisten deres Bla i alle sårbarheter