CVE Tools

CVE-2026-31431

crypto: algif_aead - Revert to operating out-of-place

Published: Apr 22, 2026Updated: Jul 15, 2026 Sources: CVE List NVD BDU csafCWE-669

Description

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system

In plain language

AI Act now

This is a Linux kernel flaw that can let a local attacker gain higher privileges on your server; if you’re running affected Linux kernels, you should update now—especially because it’s been added to the CISA Known Exploited Vulnerabilities list.

Executive summary

CVE-2026-31431 is a Linux kernel privilege-escalation flaw in the algif_aead module caused by improper handling of in-place crypto operations; it is listed in CISA KEV, meaning it’s been observed in real environments and should be treated as actively risk-bearing once reachable from a low-privilege position.

If affected, business impact
Server account takeoverFull system compromiseData theft or ransomware riskService downtime

What to do now

  1. Check whether your systems run an affected Linux kernel (on each host, confirm the exact kernel version).
  2. If you find you’re affected, plan a kernel upgrade to a fixed revision or fixed kernel package as soon as possible.
  3. Upgrade Linux kernel to one of the fixed revisions listed by upstream (example fixed git revision: 893d22e0135fa394db81df88697fba6032747667), or to the distro’s fixed kernel build (e.g., Ubuntu/Debian/RHEL/Amazon Linux/OpenShift releases that include the fix).
  4. After upgrading, verify the running kernel version matches the upgraded (fixed) one and confirm the machine reboots into the updated kernel.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 37 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 1, 2026
Remediation due:May 15, 2026

Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available
Workaround Available

References

and 164 more references View all →
11
See all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-31431 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows