CVE-2026-31431
KEV High · CVSS 7.8Linux kernel crypto algif_aead — kernel local privilege escalation / improper resource transfer (out-of-place vs in-place crypto buffer operation)
- CVSS
- 7.8
- nvd
- EPSS
- 94.5%
- 100th pct
- KEV
- Listed
- 2026-05-01
- Class
- oss containerizable
- CWE-669, CWE-1288
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Search profile — drives PoC discovery
Ranked PoCs (90) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 4001theori-io/copy-fail-CVE-2026-31431 candidateknown researcher · cited in references · recent activitygh_search · Python
- ★ 41
- ★ 20
- ★ 14
- ★ 176containerized · recent activitygh_search · C
- ★ 19
- ★ 13
- ★ 11
- ★ 432
- ★ 358
- ★ 61
- ★ 58
- ★ 55
- ★ 32
- ★ 31
- ★ 29
- ★ 25recent activitygh_search · Shell
- ★ 22
- ★ 19
- ★ 12
- ★ 10
- ★ 6
- ★ 3
- ★ 3
- ★ 3
- ★ 2
- ★ 2
- ★ 2
- ★ 2
- ★ 1
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 562
- ★ 110
- ★ 100
- ★ 74
- ★ 38
- ★ 25
- ★ 19
- ★ 18
- ★ 16
- ★ 12
- ★ 6
- ★ 4
- ★ 3
- ★ 3
- ★ 2
- ★ 2
- ★ 2
- ★ 1
- ★ 1
- ★ 1
- ★ 1
- ★ 0
- ★ 0
- ★ 0recent activitynomi_sec
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Linux | Kernel | 4.14.0 → 5.10.254 |
| Linux | Kernel | 5.11.0 → 5.15.204 |
| Linux | Kernel | 5.16.0 → 6.1.170 |
| Linux | Kernel | 6.13.0 → 6.18.22 |
| Linux | Kernel | 6.19.0 → 6.19.12 |
| Linux | Kernel | 6.2.0 → 6.6.137 |
| Linux | Kernel | 6.7.0 → 6.12.85 |
References
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- http://www.openwall.com/lists/oss-security/2026/04/29/23
- http://www.openwall.com/lists/oss-security/2026/04/29/25
- http://www.openwall.com/lists/oss-security/2026/04/29/26
- http://www.openwall.com/lists/oss-security/2026/04/30/10
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z