7.8

CVE-2026-31431 (Copy Fail)

Warning
Media report
Exploit

crypto: algif_aead - Revert to operating out-of-place

In the Linux kernel, the following vulnerability has been resolved:

crypto: algif_aead - Revert to operating out-of-place

This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.

There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings.  Get rid of
all the complexity added for in-place operation and just copy the
AD directly.
Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 4.14 < 5.10.254
LinuxLinux Kernel Version >= 5.11 < 5.15.204
LinuxLinux Kernel Version >= 5.16 < 6.1.170
LinuxLinux Kernel Version >= 6.2 < 6.6.137
LinuxLinux Kernel Version >= 6.7 < 6.12.85
LinuxLinux Kernel Version >= 6.13 < 6.18.22
LinuxLinux Kernel Version >= 6.19 < 6.19.12
LinuxLinux Kernel Version7.0 Updaterc1
LinuxLinux Kernel Version7.0 Updaterc2
LinuxLinux Kernel Version7.0 Updaterc3
LinuxLinux Kernel Version7.0 Updaterc4
LinuxLinux Kernel Version7.0 Updaterc5
LinuxLinux Kernel Version7.0 Updaterc6
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Version10.0
RedhatEnterprise Linux Version10.1
AmazonAmazon Linux Version-
CanonicalUbuntu Linux Version-
DebianDebian Linux Version11.0
DebianDebian Linux Version12.0
DebianDebian Linux Version13.0
OpensuseLeap Version15.3
OpensuseLeap Version15.4
OpensuseLeap Version15.5
OpensuseLeap Version15.6
SuseCaas Platform Version4.0
SuseEnterprise Storage Version6.0
SuseEnterprise Storage Version7.0
SuseEnterprise Storage Version7.1
SuseManager Proxy Version4.0
SuseManager Proxy Version4.1
SuseManager Proxy Version4.2
SuseManager Proxy Version4.3
SuseManager Server Version4.0
SuseManager Server Version4.1
SuseManager Server Version4.2
SuseManager Server Version4.3
SuseOpenstack Cloud Version9.0
SuseOpenstack Cloud Crowbar Version9.0
SuseBasesystem Module Version15 Updatesp1 SwPlatformsuse_linux_enterprise
SuseBasesystem Module Version15 Updatesp2 SwPlatformsuse_linux_enterprise
SuseBasesystem Module Version15 Updatesp3 SwPlatformsuse_linux_enterprise
SuseBasesystem Module Version15 Updatesp4 SwPlatformsuse_linux_enterprise
SuseBasesystem Module Version15 Updatesp5 SwPlatformsuse_linux_enterprise
SuseBasesystem Module Version15 Updatesp6 SwPlatformsuse_linux_enterprise
SuseBasesystem Module Version15 Updatesp7 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp1 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp2 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp3 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp4 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp5 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp6 SwPlatformsuse_linux_enterprise
SuseDevelopment Tools Module Version15 Updatesp7 SwPlatformsuse_linux_enterprise
SuseLegacy Module Version15 Updatesp7 SwPlatformsuse_linux_enterprise
SuseLinux Enterprise Desktop Version11 Updatesp4
SuseLinux Enterprise Desktop Version12 Updatesp4
SuseLinux Enterprise Desktop Version15 Updatesp1
SuseLinux Enterprise Desktop Version15 Updatesp2
SuseLinux Enterprise Desktop Version15 Updatesp3
SuseLinux Enterprise Desktop Version15 Updatesp4
SuseLinux Enterprise Desktop Version15 Updatesp5
SuseLinux Enterprise Desktop Version15 Updatesp6
SuseLinux Enterprise Desktop Version15 Updatesp7
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp1 SwEdition-
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp1 SwEditionespos
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp1 SwEditionltss
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp2 SwEdition-
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp2 SwEditionespos
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp2 SwEditionltss
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp3 SwEdition-
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp3 SwEditionespos
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp3 SwEditionltss
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp4 SwEdition-
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp4 SwEditionespos
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp4 SwEditionltss
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp5 SwEdition-
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp5 SwEditionespos
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp5 SwEditionltss
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp6 SwEdition-
SuseLinux Enterprise High Performance Computing Version15.0 Updatesp7 SwEdition-
SuseLinux Enterprise Live Patching Version12 Updatesp5
SuseLinux Enterprise Live Patching Version15 Updatesp4
SuseLinux Enterprise Live Patching Version15 Updatesp5
SuseLinux Enterprise Live Patching Version15 Updatesp6
SuseLinux Enterprise Live Patching Version15 Updatesp7
SuseLinux Enterprise Micro Version5.0 SwPlatform-
SuseLinux Enterprise Micro Version5.1 SwPlatform-
SuseLinux Enterprise Micro Version5.2 SwPlatform-
SuseLinux Enterprise Micro Version5.2 SwPlatformrancher
SuseLinux Enterprise Micro Version5.3 SwPlatform-
SuseLinux Enterprise Micro Version5.3 SwPlatformrancher
SuseLinux Enterprise Micro Version5.4 SwPlatform-
SuseLinux Enterprise Micro Version5.4 SwPlatformrancher
SuseLinux Enterprise Micro Version5.5 SwPlatform-
SuseLinux Enterprise Real Time Version15.0 Updatesp2
SuseLinux Enterprise Real Time Version15.0 Updatesp3
SuseLinux Enterprise Real Time Version15.0 Updatesp4
SuseLinux Enterprise Real Time Version15.0 Updatesp5
SuseLinux Enterprise Real Time Version15.0 Updatesp6
SuseLinux Enterprise Real Time Version15.0 Updatesp7
SuseLinux Enterprise Server Version11 Updatesp4 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version11 Updatesp4 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version11 Updatesp4 SwEditionltss_extreme_core SwPlatform-
SuseLinux Enterprise Server Version12 Updatesp4 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version12 Updatesp4 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version12 Updatesp4 SwEditionespos SwPlatform-
SuseLinux Enterprise Server Version12 Updatesp4 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version12 Updatesp5 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version12 Updatesp5 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version12 Updatesp5 SwEditionltss_extended_security SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp1 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp1 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version15 Updatesp1 SwEditionbusiness_critical_linux SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp1 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp2 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp2 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version15 Updatesp2 SwEditionbusiness_critical_linux SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp2 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp3 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp3 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version15 Updatesp3 SwEditionbusiness_critical_linux SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp3 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp4 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp4 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version15 Updatesp4 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp5 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp5 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version15 Updatesp5 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp6 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp6 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version15 Updatesp6 SwEditionltss SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp7 SwEdition- SwPlatform-
SuseLinux Enterprise Server Version15 Updatesp7 SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version16.0 Update- SwEdition- SwPlatform-
SuseLinux Enterprise Server Version16.0 Update- SwEdition- SwPlatformsap
SuseLinux Enterprise Server Version16.1 Update- SwEdition- SwPlatform-
SuseLinux Enterprise Server Version16.1 Update- SwEdition- SwPlatformsap
SuseLinux Micro Version6.0
SuseLinux Micro Version6.1
SuseLinux Micro Version6.2
SusePublic Cloud Module Version15 Updatesp6 SwPlatformsuse_linux_enterprise
SusePublic Cloud Module Version15 Updatesp7 SwPlatformsuse_linux_enterprise
SuseRealtime Module Version15 Updatesp3 SwPlatformsuse_linux_enterprise
SuseRealtime Module Version15 Updatesp4 SwPlatformsuse_linux_enterprise
SuseRealtime Module Version15 Updatesp5 SwPlatformsuse_linux_enterprise
SuseRealtime Module Version15 Updatesp6 SwPlatformsuse_linux_enterprise
SuseRealtime Module Version15 Updatesp7 SwPlatformsuse_linux_enterprise
VulnDex Vulnerability Enrichment
This information is available to logged-in users. Login Login

01.05.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Vulnerability

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

Description

"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Required actions
EPSS Metrics
Type Source Score percentile
EPSS FIRST.org 3.91% 0.884
CVSS Metrics
Source Base Score Exploit Score Impact Score Vector string
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-669 Incorrect Resource Transfer Between Spheres

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.