peter bassill · operator
$ cve CVE-2026-31431 JSON

CVE-2026-31431 KEV

7.8
HIGH · CVSS 3.1 · EPSS 3.4% (pctl 89)

Patch first

On CISA KEV — known exploited in the wild, due 2026-05-15.

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS3.44% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-669
On CISA KEVyes — remediate by 2026-05-15
Public exploitnone known
Published2026-04-22
Last modified2026-09-08

CISA KEV

NameLinux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Added2026-05-01
Due2026-05-15
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (40)

VendorProduct
amazonamazon linux
aristacloudvision agni
aristacloudvision portal
aristanetvisor os
aristavelocloud edge
aristavelocloud gateway
aristavelocloud orchestrator
canonicalubuntu linux
debiandebian linux
linuxlinux kernel
nixosnixos
opensuseleap
redhatenterprise linux
redhatenterprise linux aus
redhatenterprise linux eus
redhatenterprise linux tus
redhatenterprise linux update services for sap solutions
redhatopenshift container platform
siemenssimatic s7-1500 cpu 1518-4 pn\/dp mfp firmware
susebasesystem module
susecaas platform
susedevelopment tools module
suseenterprise storage
suselegacy module
suselinux enterprise desktop
suselinux enterprise high availability extension
suselinux enterprise high performance computing
suselinux enterprise live patching
suselinux enterprise micro
suselinux enterprise real time
suselinux enterprise server
suselinux enterprise workstation extension
suselinux micro
susemanager proxy
susemanager retail branch server
susemanager server
suseopenstack cloud
suseopenstack cloud crowbar
susepublic cloud module
suserealtime module

References

→ the Explorer  ·  watch your stack  ·  NVD