CVE-2026-31431 · CVSS 7.8 HIGH · EPSS 3% · KEV 2026-05-01 · patch available
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings. Get rid of
all the complexity added for in-place operation and just copy the
AD directly.
Is CVE-2026-31431 exploited?
Listed in the CISA KEV catalog on 2026-05-01.
Federal remediation due 2026-05-15.
Past that date by 138 days.
EPSS puts exploitation in the next 30 days at 3%.
Public exploit code: packaged in a public tool.
Which products and versions are affected?
Dell · Secure Connect Gateway · <5.36.00.16
Siemens · SIMATIC S7 · 1500 CPU
Red Hat · OpenShift · Container Platform <4.15.64
Docker · Desktop · <4.72.0
Siemens · SIMATIC S7 · 1500
Moxa · MXsecurity · <v2.3.3
Microsoft · azl3 kernel 6.6.134.1-2 on Azure Linux 3.0 · < 6.6.137.1-1