CVE-2026-31431

crypto: algif_aead - Revert to operating out-of-place

Basic Information

CVE State
PUBLISHED
Reserved Date
March 09, 2026
Published Date
April 22, 2026
Last Updated
May 18, 2026
Vendor
Linux
Product
Linux
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Tags
cisa

CVSS Scores

CVSS v3.1

7.8 - HIGH

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 13:26:07 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 13:26:07 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel