CVE-2026-31431
Linux Linux
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operati…
Published: 2026-04-22 · In KEV since: 2026-05-01
Analysis
🔴 Critical — actively exploited
How it's exploited: Exploitable with local access to the host, with low privileges, no user interaction, and with low complexity.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Active exploitation confirmed by CISA (KEV).
- Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
- Detect: turn this CVE into detection rules.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →
Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.