CVE-2026-31431
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 May 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.91% probability · 100th percentile
- CISA KEV
- Listed 1 May 2026 · due 15 May 2026
- Weakness
- CWE-669, CWE-1288
- Affected
- linux/linux kernel · redhat/openshift container platform · redhat/enterprise linux · redhat/enterprise linux aus · redhat/enterprise linux eus · redhat/enterprise linux tus · redhat/enterprise linux update services for sap solutions · amazon/amazon linux · canonical/ubuntu linux · debian/debian linux · opensuse/leap · suse/caas platform · suse/enterprise storage · suse/manager proxy · suse/manager retail branch server · suse/manager server · suse/openstack cloud · suse/openstack cloud crowbar · suse/basesystem module · suse/development tools module · +28 more
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CISA notes
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/; https://xint.io/blog/copy-fail-linux-distributions#the-fix-6 ; https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-31431
References
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130cPatch
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fcPatch
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667Patch
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82Patch
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875bPatch
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5Patch
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237Patch
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8Patch
- http://www.openwall.com/lists/oss-security/2026/04/29/23Exploit, Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/29/25Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/29/26Exploit, Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/10Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/11Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/12Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/14Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/15Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/16Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/17Mailing List
- http://www.openwall.com/lists/oss-security/2026/04/30/18Exploit, Mailing List
- http://www.openwall.com/lists/oss-security/2026/04/30/2Mailing List
- http://www.openwall.com/lists/oss-security/2026/04/30/20Mailing List
- http://www.openwall.com/lists/oss-security/2026/04/30/5Exploit, Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2026/04/30/6Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/10Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/12Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/15Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/16Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/17Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/18Mailing List
- http://www.openwall.com/lists/oss-security/2026/05/01/2Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.