CVE-2026-31431
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Beskrivelse
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Beskrivelsen gjengis slik kilden har publisert den, på engelsk.
Nøkkelfakta
- Publisert
- 2026-04-22
- Sist endret
- 2026-09-08
- Tildelt av
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- CVSS-vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Scoret av
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- Sannsynlighet for utnyttelse
-
94.5 %
blant de aller høyeste av alle kjente sårbarheter
EPSS, neste 30 dager, modell v2026.06.15 - Rettelse finnes
- Ja, se referansene
Aktivt utnyttet
CISA førte denne sårbarheten inn i katalogen over kjente utnyttede sårbarheter 2026-05-01, med utbedringsfrist 2026-05-15 for amerikanske føderale etater.
Pålagt tiltak: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Berørte produkter
| Leverandør | Produkt | Versjoner | Status |
|---|---|---|---|
| Amazon | Amazon Linux | alle oppførte versjoner | Berørt |
| Arista | Cloudvision Agni | ≥ 2024.4.0, ≤ 2025.2.2 | Berørt |
| Arista | Cloudvision Portal | ≥ 2024.2.0, ≤ 2026.1.0 | Berørt |
| Arista | Netvisor Os | < 7.1.0 | Berørt |
| Arista | Netvisor Os | 7.1.0 | Berørt |
| Arista | Velocloud Edge | ≥ 4.5.0, ≤ 6.4.1 | Berørt |
| Arista | Velocloud Gateway | alle oppførte versjoner | Berørt |
| Arista | Velocloud Orchestrator | alle oppførte versjoner | Berørt |
| Canonical | Ubuntu Linux | alle oppførte versjoner | Berørt |
| Canonical | Ubuntu Linux | 14.04 | Berørt |
| Canonical | Ubuntu Linux | 16.04 | Berørt |
| Canonical | Ubuntu Linux | 18.04 | Berørt |
| Canonical | Ubuntu Linux | 20.04 | Berørt |
| Canonical | Ubuntu Linux | 22.04 | Berørt |
| Canonical | Ubuntu Linux | 24.04 | Berørt |
| Canonical | Ubuntu Linux | 25.10 | Berørt |
| Debian | Debian Linux | 11.0 | Berørt |
| Debian | Debian Linux | 12.0 | Berørt |
| Debian | Debian Linux | 13.0 | Berørt |
| Linux | Linux Kernel | 7.0 | Berørt |
| Linux | Linux Kernel | ≥ 4.14, < 5.10.254 | Berørt |
| Linux | Linux Kernel | ≥ 5.11, < 5.15.204 | Berørt |
| Linux | Linux Kernel | ≥ 5.16, < 6.1.170 | Berørt |
| Linux | Linux Kernel | ≥ 6.13, < 6.18.22 | Berørt |
| Linux | Linux Kernel | ≥ 6.19, < 6.19.12 | Berørt |
| Linux | Linux Kernel | ≥ 6.2, < 6.6.137 | Berørt |
| Linux | Linux Kernel | ≥ 6.7, < 6.12.85 | Berørt |
| Nixos | Nixos | < 25.11 | Berørt |
| Opensuse | Leap | 15.3 | Berørt |
| Opensuse | Leap | 15.4 | Berørt |
| Opensuse | Leap | 15.5 | Berørt |
| Opensuse | Leap | 15.6 | Berørt |
| Redhat | Enterprise Linux | 10.0 | Berørt |
| Redhat | Enterprise Linux | 8.0 | Berørt |
| Redhat | Enterprise Linux | 9.0 | Berørt |
| Redhat | Enterprise Linux Aus | 8.4 | Berørt |
| Redhat | Enterprise Linux Aus | 8.6 | Berørt |
| Redhat | Enterprise Linux Eus | 10.0 | Berørt |
| Redhat | Enterprise Linux Eus | 8.4 | Berørt |
| Redhat | Enterprise Linux Eus | 9.4 | Berørt |
| Redhat | Enterprise Linux Eus | 9.6 | Berørt |
| Redhat | Enterprise Linux Tus | 8.6 | Berørt |
| Redhat | Enterprise Linux Tus | 8.8 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.6 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.8 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.0 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.2 | Berørt |
| Redhat | Openshift Container Platform | 4.0 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.12, < 4.12.89 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.13, < 4.13.66 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.14, < 4.14.65 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.15, < 4.15.64 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.16, < 4.16.61 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.17, < 4.17.53 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.18, < 4.18.40 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.19, < 4.19.30 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.20, < 4.20.21 | Berørt |
| Redhat | Openshift Container Platform | ≥ 4.21, < 4.21.14 | Berørt |
| Siemens | Simatic Ax Runtime | alle oppførte versjoner | Berørt |
| Siemens | Simatic Cn 4100 | alle oppførte versjoner | Ikke berørt |
Svakhetstype
-
CWE-1288: Improper Validation of Consistency within Input
The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.
-
CWE-669: Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Referanser
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- http://www.openwall.com/lists/oss-security/2026/04/29/23
- http://www.openwall.com/lists/oss-security/2026/04/29/25
- http://www.openwall.com/lists/oss-security/2026/04/29/26
- http://www.openwall.com/lists/oss-security/2026/04/30/10
- http://www.openwall.com/lists/oss-security/2026/04/30/11
- http://www.openwall.com/lists/oss-security/2026/04/30/12
- http://www.openwall.com/lists/oss-security/2026/04/30/14
- http://www.openwall.com/lists/oss-security/2026/04/30/15
- http://www.openwall.com/lists/oss-security/2026/04/30/16
- http://www.openwall.com/lists/oss-security/2026/04/30/17
- http://www.openwall.com/lists/oss-security/2026/04/30/18
- http://www.openwall.com/lists/oss-security/2026/04/30/2
Relatert hos Berigo
Artikler
-
Ny rettighetseskalering i Linux-kjernen uten tilgjengelig oppdatering
Nevner denne CVE-en
2026-05-07
En ny sårbarhet i Linux-kjernen, kalt dirty frag, gir lokal rettighetseskalering i alle versjoner siden 2017, og det finnes ingen oppdatering ennå.
-
Copy Fail gir lokale brukere rottilgang på de fleste Linux-systemer
Nevner denne CVE-en
2026-04-29
CVE-2026-31431 lar en vanlig bruker skaffe seg rottilgang på de fleste Linux-distribusjoner, og utnyttelseskode er allerede publisert.
Berører dette dere?
En sårbarhet betyr bare noe hvis dere kjører produktet, i en berørt versjon, et sted en angriper kommer til.