CVE Tools

CVE-2026-31431

crypto: algif_aead - Revert to operating out-of-place

Published: Apr 22, 2026Updated: Jul 28, 2026 Sources: CVE List NVD BDU csafCWE-669

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

In plain language

AI Act now

This is a Linux kernel flaw that can let a local attacker gain higher privileges on your server; if you’re running affected Linux kernels, you should update now—especially because it’s been added to the CISA Known Exploited Vulnerabilities list.

Executive summary

CVE-2026-31431 is a Linux kernel privilege-escalation flaw in the algif_aead module caused by improper handling of in-place crypto operations; it is listed in CISA KEV, meaning it’s been observed in real environments and should be treated as actively risk-bearing once reachable from a low-privilege position.

If affected, business impact
Server account takeoverFull system compromiseData theft or ransomware riskService downtime

What to do now

  1. Check whether your systems run an affected Linux kernel (on each host, confirm the exact kernel version).
  2. If you find you’re affected, plan a kernel upgrade to a fixed revision or fixed kernel package as soon as possible.
  3. Upgrade Linux kernel to one of the fixed revisions listed by upstream (example fixed git revision: 893d22e0135fa394db81df88697fba6032747667), or to the distro’s fixed kernel build (e.g., Ubuntu/Debian/RHEL/Amazon Linux/OpenShift releases that include the fix).
  4. After upgrading, verify the running kernel version matches the upgraded (fixed) one and confirm the machine reboots into the updated kernel.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 34 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 1, 2026
Remediation due:May 15, 2026

Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available
Workaround Available

References

and 626 more references View all →
14
See all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-31431 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows