CVE-2026-31431: Linux Kernel algif_aead KEV Vulnerability
CVE-2026-31431 affects Linux kernel algif_aead ranges and is listed in CISA KEV; affected fleets should patch by the vendor deadline.
CVE-2026-31431 is a vulnerability published by NVD on 22/04/2026.
What happened
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings. Get rid of
all the complexity added for in-place operation and just copy the
AD directly.
Affected products and versions
- linux linux kernel unspecified version (from 4.14 before 5.10.254)
- linux linux kernel unspecified version (from 5.11 before 5.15.204)
- linux linux kernel unspecified version (from 5.16 before 6.1.170)
- linux linux kernel unspecified version (from 6.2 before 6.6.137)
- linux linux kernel unspecified version (from 6.7 before 6.12.85)
- linux linux kernel unspecified version (from 6.13 before 6.18.22)
- linux linux kernel unspecified version (from 6.19 before 6.19.12)
- linux linux kernel 7.0
- linux linux kernel 7.0
- linux linux kernel 7.0
- linux linux kernel 7.0
- linux linux kernel 7.0
- linux linux kernel 7.0
- redhat openshift container platform 4.0
- redhat enterprise linux 8.0
- redhat enterprise linux 9.0
- redhat enterprise linux 10.0
- redhat enterprise linux 10.1
- amazon amazon linux -
- canonical ubuntu linux -
Severity and weakness
CVSS: HIGH 7.8. Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Weaknesses: CWE-669.
Known exploitation
CISA KEV status: added 2026-05-01. Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.. Due date: 2026-05-15.
What defenders should do
- Identify whether the affected product and version range exists in production.
- Review vendor advisories and release notes before change windows.
- Patch, upgrade, disable the vulnerable component, or apply vendor mitigations.
- Verify the running version after deployment, not only the package inventory.
Official and supporting references
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- http://www.openwall.com/lists/oss-security/2026/04/29/23
- http://www.openwall.com/lists/oss-security/2026/04/29/25
- http://www.openwall.com/lists/oss-security/2026/04/29/26
- http://www.openwall.com/lists/oss-security/2026/04/30/10