HarborGuard / CVE
Back to search
HIGHCVE-2026-31431Published Modified CNA Linux

CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
*
Affected Products
2

Fix available

*019d43105a97be0810edbda875f2cd03f30dc130c3115af9644c342b356f3f07a4dd1c8905cd9a6fc5.10.2545.15.2046.1.1706.6.1376.12.856.18.226.19.127.0893d22e0135fa394db81df88697fba60327476678b88d99341f139e23bdeb1027a2a3ae10d341d82961cfa271a918ad4ae452420e7c303149002875ba664bf3d603dc3bdcf9ae47cc21e0daec706d7a5ce42ee423e58dffa5ec03524054c9d8bfd4f6237fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
Affected packages
  • Linux / Linux
    < 893d22e0135fa394db81df88697fba6032747667 (from 72548b093ee38a6d4f2a19e6ef1948ae05c181f7) · < 19d43105a97be0810edbda875f2cd03f30dc130c (from 72548b093ee38a6d4f2a19e6ef1948ae05c181f7) · < 961cfa271a918ad4ae452420e7c303149002875b (from 72548b093ee38a6d4f2a19e6ef1948ae05c181f7) · < 3115af9644c342b356f3f07a4dd1c8905cd9a6fc (from 72548b093ee38a6d4f2a19e6ef1948ae05c181f7) · < 8b88d99341f139e23bdeb1027a2a3ae10d341d82 (from 72548b093ee38a6d4f2a19e6ef1948ae05c181f7) · < fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 (from 72548b093ee38a6d4f2a19e6ef1948ae05c181f7)
  • Linux / Linux
    4.14
    Fixed in 0, 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H