CVE-2026-31431High· 7.8▾ Abyssal⚠ Exploited in the wildPoC availableIn the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 20 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 15, 2026
96%
96% → 100%
Last analysed / modified upstream
319 GitHub repos · Metasploit ×1
Added to the CISA catalog on May 1, 2026. Federal remediation due May 15, 2026. View catalog ↗
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of the associated data.
There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
linux_kernel >= 4.14, < 5.10.254linux_kernel >= 5.11, < 5.15.204linux_kernel >= 5.16, < 6.1.170linux_kernel >= 6.2, < 6.6.137linux_kernel >= 6.7, < 6.12.85linux_kernel >= 6.13, < 6.18.22linux_kernel >= 6.19, < 6.19.12linux_kernel = 7.0openshift_container_platform >= 4.12, < 4.12.89openshift_container_platform >= 4.13, < 4.13.66openshift_container_platform >= 4.14, < 4.14.65openshift_container_platform >= 4.15, < 4.15.64openshift_container_platform >= 4.16, < 4.16.61openshift_container_platform >= 4.17, < 4.17.53openshift_container_platform >= 4.18, < 4.18.40openshift_container_platform >= 4.19, < 4.19.30openshift_container_platform >= 4.20, < 4.20.21openshift_container_platform >= 4.21, < 4.21.14openshift_container_platform = 4.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0enterprise_linux_aus = 8.4enterprise_linux_aus = 8.6enterprise_linux_eus = 8.4enterprise_linux_eus = 9.4enterprise_linux_eus = 9.6enterprise_linux_eus = 10.0enterprise_linux_tus = 8.6enterprise_linux_tus = 8.8enterprise_linux_update_services_for_sap_solutions = 8.6enterprise_linux_update_services_for_sap_solutions = 8.8enterprise_linux_update_services_for_sap_solutions = 9.0enterprise_linux_update_services_for_sap_solutions = 9.2amazon_linuxubuntu_linuxdebian_linux = 11.0debian_linux = 12.0debian_linux = 13.0leap = 15.3leap = 15.4leap = 15.5leap = 15.6caas_platform = 4.0enterprise_storage = 6.0enterprise_storage = 7.0enterprise_storage = 7.1manager_proxy = 4.0manager_proxy = 4.1manager_proxy = 4.2manager_proxy = 4.3manager_retail_branch_server = 4.0manager_retail_branch_server = 4.1manager_retail_branch_server = 4.2manager_retail_branch_server = 4.3manager_server = 4.0manager_server = 4.1manager_server = 4.2manager_server = 4.3openstack_cloud = 9.0openstack_cloud_crowbar = 9.0basesystem_module = 15development_tools_module = 15legacy_module = 15linux_enterprise_desktop = 11linux_enterprise_desktop = 12linux_enterprise_desktop = 15linux_enterprise_high_availability_extension = 15linux_enterprise_high_availability_extension = 16.0linux_enterprise_high_performance_computing = 15.0linux_enterprise_live_patching = 12linux_enterprise_live_patching = 15linux_enterprise_micro = 5.0linux_enterprise_micro = 5.1linux_enterprise_micro = 5.2linux_enterprise_micro = 5.3linux_enterprise_micro = 5.4linux_enterprise_micro = 5.5linux_enterprise_real_time = 15.0linux_enterprise_server = 11linux_enterprise_server = 12linux_enterprise_server = 15linux_enterprise_server = 16.0linux_enterprise_server = 16.1linux_enterprise_workstation_extension = 15linux_micro = 6.0linux_micro = 6.1linux_micro = 6.2public_cloud_module = 15realtime_module = 15nixos < 25.11cloudvision_agni >= 2024.4.0, <= 2025.2.2cloudvision_portal >= 2024.2.0, <= 2026.1.0velocloud_edge >= 4.5.0, <= 6.4.1velocloud_gatewayvelocloud_orchestratornetvisor_os < 7.1.0netvisor_os = 7.1.0simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware >= 3.1.5simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware >= 3.1.5Upgrade past the affected range:
linux_kernel 6.19.12openshift_container_platform 4.21.14nixos 25.11netvisor_os 7.1.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-4408Critical· 9.0A flaw was found in Samba
CVE-2026-42965High· 7.7A flaw was found in the OpenShift Router
CVE-2026-18209Low· 3.4A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows
CVE-2026-54100High· 8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
CVE-2026-1784High· 8.8The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy