CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
In plain language
AI Act nowThis is a Linux kernel flaw that can let a local attacker gain higher privileges on your server; if you’re running affected Linux kernels, you should update now—especially because it’s been added to the CISA Known Exploited Vulnerabilities list.
CVE-2026-31431 is a Linux kernel privilege-escalation flaw in the algif_aead module caused by improper handling of in-place crypto operations; it is listed in CISA KEV, meaning it’s been observed in real environments and should be treated as actively risk-bearing once reachable from a low-privilege position.
What to do now
- Check whether your systems run an affected Linux kernel (on each host, confirm the exact kernel version).
- If you find you’re affected, plan a kernel upgrade to a fixed revision or fixed kernel package as soon as possible.
- Upgrade Linux kernel to one of the fixed revisions listed by upstream (example fixed git revision: 893d22e0135fa394db81df88697fba6032747667), or to the distro’s fixed kernel build (e.g., Ubuntu/Debian/RHEL/Amazon Linux/OpenShift releases that include the fix).
- After upgrading, verify the running kernel version matches the upgraded (fixed) one and confirm the machine reboots into the updated kernel.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- Exploits and vulnerabilities in Q2 2026en-us·Kaspersky Securelist· PoC Windows Defender zero-day
- Copy Fail. Как четыре байта дают root в Linuxru-ru·Хакер (xakep.ru)· PoC Linux Kernel privilege-escalation
- Three in four AI-generated vulnerability patches leave something brokenen-us·Help Net Security· Research ai-ml
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministryen·The Hacker News· Incident Hermes AI agent ai-ml
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distrosen·The Hacker News· PoC privilege-escalation
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Androiden·The Hacker News· PoC linux kernel privilege-escalation
- Linux-уязвимость DirtyClone помогает повысить права до уровня rootru-ru·Хакер (xakep.ru)· PoC Linux kernel privilege-escalation
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packetsen·The Hacker News· PoC Linux Kernel rce
- Июньский «В тренде VM»: уязвимости ядра Linux, Microsoft Defender и устройств Palo Alto Networksru·Хабр — Информационная безопасность· Roundup Linux kernel
- Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Modelsen·The Hacker News· PoC open-weight LLM ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-31431 and every CVE in our database. Create a free account — no credit card required.
Create Free Account