Fiche vulnérabilité
CVE-2026-31431 : faille exploitée linux linux kernel (CVSS 7.8)
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 22 avr. 2026
- Dernière mise à jour
- 8 sept. 2026
Produits concernés
- linux linux kernel
- redhat openshift container platform
- redhat enterprise linux
- redhat enterprise linux aus
- redhat enterprise linux eus
- redhat enterprise linux tus
- redhat enterprise linux update services for sap solutions
- amazon amazon linux
- canonical ubuntu linux
- debian debian linux
- opensuse leap
- suse caas platform
- suse enterprise storage
- suse manager proxy
- suse manager retail branch server
- suse manager server
- suse openstack cloud
- suse openstack cloud crowbar
- suse basesystem module
- suse development tools module
Correctif et mesures
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Références
- Fiche CVE-2026-31431 sur le NVD (NIST)
- git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc1…
- git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a…
- git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747…
- git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341…
- git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c3031490028…
- git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d…
- git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6…
- git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9ae…
- openwall.com/lists/oss-security/2026/04/29/23
- openwall.com/lists/oss-security/2026/04/29/25
- openwall.com/lists/oss-security/2026/04/29/26
- openwall.com/lists/oss-security/2026/04/30/10
- openwall.com/lists/oss-security/2026/04/30/11
- openwall.com/lists/oss-security/2026/04/30/12
- openwall.com/lists/oss-security/2026/04/30/14