CVE-2026-31431
Last modified
CVE-2026-31431 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.91% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 4.14, < 5.10.254 | — |
| Linux | Linux Kernel | >= 5.11, < 5.15.204 | — |
| Linux | Linux Kernel | >= 5.16, < 6.1.170 | — |
| Linux | Linux Kernel | >= 6.2, < 6.6.137 | — |
| Linux | Linux Kernel | >= 6.7, < 6.12.85 | — |
| Linux | Linux Kernel | >= 6.13, < 6.18.22 | — |
| Linux | Linux Kernel | >= 6.19, < 6.19.12 | — |
| Linux | Linux Kernel | 7.0 | Rc1 |
| Redhat | Openshift Container Platform | >= 4.12, < 4.12.89 | — |
| Redhat | Openshift Container Platform | >= 4.13, < 4.13.66 | — |
| Redhat | Openshift Container Platform | >= 4.14, < 4.14.65 | — |
| Redhat | Openshift Container Platform | >= 4.15, < 4.15.64 | — |
| Redhat | Openshift Container Platform | >= 4.16, < 4.16.61 | — |
| Redhat | Openshift Container Platform | >= 4.17, < 4.17.53 | — |
| Redhat | Openshift Container Platform | >= 4.18, < 4.18.40 | — |
| Redhat | Openshift Container Platform | >= 4.19, < 4.19.30 | — |
| Redhat | Openshift Container Platform | >= 4.20, < 4.20.21 | — |
| Redhat | Openshift Container Platform | >= 4.21, < 4.21.14 | — |
| Redhat | Openshift Container Platform | 4.0 | — |
| Redhat | Enterprise Linux | 8.0 | — |
| Redhat | Enterprise Linux | 9.0 | — |
| Redhat | Enterprise Linux | 10.0 | — |
| Redhat | Enterprise Linux Aus | 8.4 | — |
| Redhat | Enterprise Linux Aus | 8.6 | — |
| Redhat | Enterprise Linux Eus | 8.4 | — |
| Redhat | Enterprise Linux Eus | 9.4 | — |
| Redhat | Enterprise Linux Eus | 9.6 | — |
| Redhat | Enterprise Linux Eus | 10.0 | — |
| Redhat | Enterprise Linux Tus | 8.6 | — |
| Redhat | Enterprise Linux Tus | 8.8 | — |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.6 | — |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.8 | — |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.0 | — |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.2 | — |
| Amazon | Amazon Linux | All versions | — |
| Canonical | Ubuntu Linux | All versions | — |
| Debian | Debian Linux | 11.0 | — |
| Debian | Debian Linux | 12.0 | — |
| Debian | Debian Linux | 13.0 | — |
| Opensuse | Leap | 15.3 | — |
| Opensuse | Leap | 15.4 | — |
| Opensuse | Leap | 15.5 | — |
| Opensuse | Leap | 15.6 | — |
| Suse | Caas Platform | 4.0 | — |
| Suse | Enterprise Storage | 6.0 | — |
| Suse | Enterprise Storage | 7.0 | — |
| Suse | Enterprise Storage | 7.1 | — |
| Suse | Manager Proxy | 4.0 | — |
| Suse | Manager Proxy | 4.1 | — |
| Suse | Manager Proxy | 4.2 | — |
Showing 50 of 115 affected configurations. See NVD for the full list.
References
- https://www.openwall.com/lists/oss-security/2026/04/29/23Exploit, Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/29/25Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/29/26Exploit, Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/10Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/11Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/12Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/14Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/15Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/16Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2026/04/30/18Exploit, Mailing List
- https://www.openwall.com/lists/oss-security/2026/04/30/5Exploit, Mailing List, Patch
- https://copy.failExploit
- https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170Exploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/260001Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13565Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13566Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13577Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13578Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13681Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13690Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13727Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13734Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13811Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13862Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13885Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13887Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13932Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:13936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14097Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14137Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14165Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14230Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14301Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14339Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14773Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:14926Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:15087Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:15976Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:15978Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16063Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16111Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16208Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16209Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16210Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:19074Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:19225Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33486Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-31431Third Party Advisory
- https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigationThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460538Issue Tracking, Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-265688.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-328642.htmlThird Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31431.jsonThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431US Government Resource
- https://xint.io/blog/copy-fail-linux-distributions#the-fix-6Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-31431?
How severe is CVE-2026-31431?
How do I fix CVE-2026-31431?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-31426In the Linux kernel, the following vulnerability has been re…7
- CVE-2026-31427In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31428In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31429In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-3143The Total Upkeep – WordPress Backup Plugin plus Restore & Mi…5.3
- CVE-2026-31430In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-31432In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-31433In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-31434In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31435In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-31436In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-31437In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2026-31431?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
