CVE-2026-31431
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since May 1, 2026
- US federal agencies must remediate it by May 15, 2026 (BOD 22-01)
- First attack observed 9 days after disclosure
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 9, 2026 Sep 1, 2026 Aug 26, 2026 Aug 3, 2026 Aug 3, 2026 Jul 15, 2026
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| linux | linux kernel | < 5.10.254 |
| redhat | openshift container platform | < 4.12.89 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux aus | 8.4 |
| redhat | enterprise linux eus | 8.4 |
| redhat | enterprise linux tus | 8.6 |
| redhat | enterprise linux update services for sap solutions | 8.6 |
| amazon | amazon linux | - |
| canonical | ubuntu linux | - |
| debian | debian linux | 11.0 |
| opensuse | leap | 15.3 |
| suse | caas platform | 4.0 |
| suse | enterprise storage | 6.0 |
| suse | manager proxy | 4.0 |
| suse | manager retail branch server | 4.0 |
| suse | manager server | 4.0 |
| suse | openstack cloud | 9.0 |
| suse | openstack cloud crowbar | 9.0 |
| suse | basesystem module | 15 |
| suse | development tools module | 15 |
| suse | legacy module | 15 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise high availability extension | 15 |
| suse | linux enterprise high performance computing | 15.0 |
| suse | linux enterprise live patching | 12 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
