CVE-2026-31431

HIGH CISA KEV
Published Apr 22, 2026 Modified May 12, 2026 CWE-669

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVSS v3.1 Score

7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS — Exploit Prediction

0.0257
Probability of exploitation
0.86%
Percentile rank

EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: May 1, 2026 Remediation due: May 15, 2026

Weakness Type (CWE)

CWE-669 CWE-669

Affected Products

Vendor Product
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
linux linux_kernel
redhat openshift_container_platform
redhat enterprise_linux
redhat enterprise_linux
redhat enterprise_linux
redhat enterprise_linux
amazon amazon_linux
canonical ubuntu_linux
debian debian_linux
debian debian_linux
debian debian_linux
opensuse leap
opensuse leap
opensuse leap
opensuse leap
suse caas_platform
suse enterprise_storage
suse enterprise_storage
suse enterprise_storage
suse manager_proxy
suse manager_proxy
suse manager_proxy
suse manager_proxy
suse manager_retail_branch_server
suse manager_retail_branch_server
suse manager_retail_branch_server
suse manager_retail_branch_server
suse manager_server
suse manager_server
suse manager_server
suse manager_server
suse openstack_cloud
suse openstack_cloud_crowbar
suse basesystem_module
suse basesystem_module
suse basesystem_module
suse basesystem_module
suse basesystem_module
suse basesystem_module
suse basesystem_module
suse development_tools_module
suse development_tools_module
suse development_tools_module
suse development_tools_module
suse development_tools_module
suse development_tools_module
suse development_tools_module
suse legacy_module
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_desktop
suse linux_enterprise_high_availability_extension
suse linux_enterprise_high_availability_extension
suse linux_enterprise_high_availability_extension
suse linux_enterprise_high_availability_extension
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_high_performance_computing
suse linux_enterprise_live_patching
suse linux_enterprise_live_patching
suse linux_enterprise_live_patching
suse linux_enterprise_live_patching
suse linux_enterprise_live_patching
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_micro
suse linux_enterprise_real_time
suse linux_enterprise_real_time
suse linux_enterprise_real_time
suse linux_enterprise_real_time
suse linux_enterprise_real_time
suse linux_enterprise_real_time
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_server
suse linux_enterprise_workstation_extension
suse linux_micro
suse linux_micro
suse linux_micro
suse public_cloud_module
suse public_cloud_module
suse realtime_module
suse realtime_module
suse realtime_module
suse realtime_module
suse realtime_module
nixos nixos
arista cloudvision_agni
arista cloudvision_portal
arista velocloud_edge
arista velocloud_gateway
vmware velocloud_orchestrator
arista netvisor_os
arista netvisor_os
arista netvisor_os
siemens simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware
siemens simatic_s7-1500_cpu_1518-4_pn\/dp_mfp
siemens simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware
siemens simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp
siemens siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware
siemens siplus_s7-1500_cpu_1518-4_pn\/dp_mfp
siemens simatic_s7-1500_tm_mfp_firmware
siemens simatic_s7-1500_tm_mfp

References

Advisories & Patches

Frequently Asked Questions

What is CVE-2026-31431? +
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. It has a CVSS v3.1 base score of 7.8 (HIGH). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2026-31431? +
CVE-2026-31431 has a CVSS v3.1 score of 7.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching. The EPSS score is 0.0257, placing it in the 1th percentile for exploitation probability.
What products are affected by CVE-2026-31431? +
CVE-2026-31431 affects products from amazon, arista, canonical, debian, linux, nixos, opensuse, redhat, siemens, suse, vmware, specifically: amazon_linux, basesystem_module, caas_platform, cloudvision_agni, cloudvision_portal, debian_linux, development_tools_module, enterprise_linux, enterprise_storage, leap, legacy_module, linux_enterprise_desktop, linux_enterprise_high_availability_extension, linux_enterprise_high_performance_computing, linux_enterprise_live_patching, linux_enterprise_micro, linux_enterprise_real_time, linux_enterprise_server, linux_enterprise_workstation_extension, linux_kernel, linux_micro, manager_proxy, manager_retail_branch_server, manager_server, netvisor_os, nixos, openshift_container_platform, openstack_cloud, openstack_cloud_crowbar, public_cloud_module, realtime_module, simatic_s7-1500_cpu_1518-4_pn\/dp_mfp, simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware, simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp, simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware, simatic_s7-1500_tm_mfp, simatic_s7-1500_tm_mfp_firmware, siplus_s7-1500_cpu_1518-4_pn\/dp_mfp, siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware, ubuntu_linux, velocloud_edge, velocloud_gateway, velocloud_orchestrator. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2026-31431? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2026-31431 — free, no signup required.

Start Free Scan