HIGH · 7.8

CVE-2026-31431

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associ...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 4.14, < 5.10.254
RedhatOpenshift Container Platform>= 4.12, < 4.12.89
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Aus8.4
RedhatEnterprise Linux Eus8.4
RedhatEnterprise Linux Tus8.6
RedhatEnterprise Linux Update Services For Sap Solutions8.6
AmazonAmazon Linux-
CanonicalUbuntu Linux-
DebianDebian Linux11.0
OpensuseLeap15.3
SuseCaas Platform4.0
SuseEnterprise Storage6.0
SuseManager Proxy4.0
SuseManager Retail Branch Server4.0
SuseManager Server4.0
SuseOpenstack Cloud9.0
SuseOpenstack Cloud Crowbar9.0
SuseBasesystem Module15
SuseDevelopment Tools Module15

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-31431?

CVE-2026-31431 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associ...

How severe is CVE-2026-31431?

CVE-2026-31431 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-31431?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Openshift Container Platform, Redhat Enterprise Linux, Redhat Enterprise Linux Aus, Redhat Enterprise Linux Eus.