CVE-2026-31431
Nel kernel Linux è stata risolta la seguente vulnerabilità: crypto: algif_aead - Ripristino dell'operatività out-of-place Questo annulla in gran parte il commit 72548b093ee3, fatta eccezione per la copia dei dati associati. Non vi è alcun vantaggio nell'operare in-place in algif_aead, poiché origine e destinazione provengono da mapping diversi. Eliminare tutta la complessità aggiunta per l'operatività in-place e copiare semplicemente direttamente l'AD.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 1 mag 2026
- Le agenzie federali statunitensi devono correggerla entro il 15 mag 2026 (direttiva BOD 22-01)
- Primo attacco osservato 9 giorni dopo la divulgazione
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Fonte: CISA KEV · 9 set 2026 1 set 2026 26 ago 2026 3 ago 2026 3 ago 2026 15 lug 2026
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HProdotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 5.10.254 |
| redhat | openshift container platform | < 4.12.89 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux aus | 8.4 |
| redhat | enterprise linux eus | 8.4 |
| redhat | enterprise linux tus | 8.6 |
| redhat | enterprise linux update services for sap solutions | 8.6 |
| amazon | amazon linux | - |
| canonical | ubuntu linux | - |
| debian | debian linux | 11.0 |
| opensuse | leap | 15.3 |
| suse | caas platform | 4.0 |
| suse | enterprise storage | 6.0 |
| suse | manager proxy | 4.0 |
| suse | manager retail branch server | 4.0 |
| suse | manager server | 4.0 |
| suse | openstack cloud | 9.0 |
| suse | openstack cloud crowbar | 9.0 |
| suse | basesystem module | 15 |
| suse | development tools module | 15 |
| suse | legacy module | 15 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise high availability extension | 15 |
| suse | linux enterprise high performance computing | 15.0 |
| suse | linux enterprise live patching | 12 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.
