CVE-2026-31431 KEV
7.8
HIGH · CVSS 3.1 · EPSS 3.4% (pctl 89)
Patch first
On CISA KEV — known exploited in the wild, due 2026-05-15.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.44% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-669 |
| On CISA KEV | yes — remediate by 2026-05-15 |
| Public exploit | none known |
| Published | 2026-04-22 |
| Last modified | 2026-09-08 |
CISA KEV
| Name | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability |
|---|---|
| Added | 2026-05-01 |
| Due | 2026-05-15 |
| Vendor / product | Linux / Kernel |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| amazon | amazon linux |
| arista | cloudvision agni |
| arista | cloudvision portal |
| arista | netvisor os |
| arista | velocloud edge |
| arista | velocloud gateway |
| arista | velocloud orchestrator |
| canonical | ubuntu linux |
| debian | debian linux |
| linux | linux kernel |
| nixos | nixos |
| opensuse | leap |
| redhat | enterprise linux |
| redhat | enterprise linux aus |
| redhat | enterprise linux eus |
| redhat | enterprise linux tus |
| redhat | enterprise linux update services for sap solutions |
| redhat | openshift container platform |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware |
| suse | basesystem module |
| suse | caas platform |
| suse | development tools module |
| suse | enterprise storage |
| suse | legacy module |
| suse | linux enterprise desktop |
| suse | linux enterprise high availability extension |
| suse | linux enterprise high performance computing |
| suse | linux enterprise live patching |
| suse | linux enterprise micro |
| suse | linux enterprise real time |
| suse | linux enterprise server |
| suse | linux enterprise workstation extension |
| suse | linux micro |
| suse | manager proxy |
| suse | manager retail branch server |
| suse | manager server |
| suse | openstack cloud |
| suse | openstack cloud crowbar |
| suse | public cloud module |
| suse | realtime module |
References
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- http://www.openwall.com/lists/oss-security/2026/04/29/23
- http://www.openwall.com/lists/oss-security/2026/04/29/25
- http://www.openwall.com/lists/oss-security/2026/04/29/26
- http://www.openwall.com/lists/oss-security/2026/04/30/10
- http://www.openwall.com/lists/oss-security/2026/04/30/11
- http://www.openwall.com/lists/oss-security/2026/04/30/12
- http://www.openwall.com/lists/oss-security/2026/04/30/14
- http://www.openwall.com/lists/oss-security/2026/04/30/15
- http://www.openwall.com/lists/oss-security/2026/04/30/16
- http://www.openwall.com/lists/oss-security/2026/04/30/17
- http://www.openwall.com/lists/oss-security/2026/04/30/18
- http://www.openwall.com/lists/oss-security/2026/04/30/2
→ the Explorer · watch your stack · NVD