---
id: CVE-2026-31431
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: algif_aead - Revert to operating out-of-place

  This mostly reverts commit 72548b093ee3 except for the copying of
  the associated data.

  There is no benefit in op…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: algif_aead - Revert to operating out-of-place

  This mostly reverts commit 72548b093ee3 except for the copying of
  the associated data.

  There is no benefit in op…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-669
  - CWE-1288
vendor: redhat
product: openshift_container_platform
affected:
  - 'linux_kernel >= 4.14, < 5.10.254'
  - 'linux_kernel >= 5.11, < 5.15.204'
  - 'linux_kernel >= 5.16, < 6.1.170'
  - 'linux_kernel >= 6.2, < 6.6.137'
  - 'linux_kernel >= 6.7, < 6.12.85'
  - 'linux_kernel >= 6.13, < 6.18.22'
  - 'linux_kernel >= 6.19, < 6.19.12'
  - linux_kernel = 7.0
  - 'openshift_container_platform >= 4.12, < 4.12.89'
  - 'openshift_container_platform >= 4.13, < 4.13.66'
  - 'openshift_container_platform >= 4.14, < 4.14.65'
  - 'openshift_container_platform >= 4.15, < 4.15.64'
  - 'openshift_container_platform >= 4.16, < 4.16.61'
  - 'openshift_container_platform >= 4.17, < 4.17.53'
  - 'openshift_container_platform >= 4.18, < 4.18.40'
  - 'openshift_container_platform >= 4.19, < 4.19.30'
  - 'openshift_container_platform >= 4.20, < 4.20.21'
  - 'openshift_container_platform >= 4.21, < 4.21.14'
  - openshift_container_platform = 4.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
  - enterprise_linux_aus = 8.4
  - enterprise_linux_aus = 8.6
  - enterprise_linux_eus = 8.4
  - enterprise_linux_eus = 9.4
  - enterprise_linux_eus = 9.6
  - enterprise_linux_eus = 10.0
  - enterprise_linux_tus = 8.6
  - enterprise_linux_tus = 8.8
  - enterprise_linux_update_services_for_sap_solutions = 8.6
  - enterprise_linux_update_services_for_sap_solutions = 8.8
  - enterprise_linux_update_services_for_sap_solutions = 9.0
  - enterprise_linux_update_services_for_sap_solutions = 9.2
  - amazon_linux
  - ubuntu_linux
  - debian_linux = 11.0
  - debian_linux = 12.0
  - debian_linux = 13.0
  - leap = 15.3
  - leap = 15.4
  - leap = 15.5
  - leap = 15.6
  - caas_platform = 4.0
  - enterprise_storage = 6.0
  - enterprise_storage = 7.0
  - enterprise_storage = 7.1
  - manager_proxy = 4.0
  - manager_proxy = 4.1
  - manager_proxy = 4.2
  - manager_proxy = 4.3
  - manager_retail_branch_server = 4.0
  - manager_retail_branch_server = 4.1
  - manager_retail_branch_server = 4.2
  - manager_retail_branch_server = 4.3
  - manager_server = 4.0
  - manager_server = 4.1
  - manager_server = 4.2
  - manager_server = 4.3
  - openstack_cloud = 9.0
  - openstack_cloud_crowbar = 9.0
  - basesystem_module = 15
  - development_tools_module = 15
  - legacy_module = 15
  - linux_enterprise_desktop = 11
  - linux_enterprise_desktop = 12
  - linux_enterprise_desktop = 15
  - linux_enterprise_high_availability_extension = 15
  - linux_enterprise_high_availability_extension = 16.0
  - linux_enterprise_high_performance_computing = 15.0
  - linux_enterprise_live_patching = 12
  - linux_enterprise_live_patching = 15
  - linux_enterprise_micro = 5.0
  - linux_enterprise_micro = 5.1
  - linux_enterprise_micro = 5.2
  - linux_enterprise_micro = 5.3
  - linux_enterprise_micro = 5.4
  - linux_enterprise_micro = 5.5
  - linux_enterprise_real_time = 15.0
  - linux_enterprise_server = 11
  - linux_enterprise_server = 12
  - linux_enterprise_server = 15
  - linux_enterprise_server = 16.0
  - linux_enterprise_server = 16.1
  - linux_enterprise_workstation_extension = 15
  - linux_micro = 6.0
  - linux_micro = 6.1
  - linux_micro = 6.2
  - public_cloud_module = 15
  - realtime_module = 15
  - nixos < 25.11
  - 'cloudvision_agni >= 2024.4.0, <= 2025.2.2'
  - 'cloudvision_portal >= 2024.2.0, <= 2026.1.0'
  - 'velocloud_edge >= 4.5.0, <= 6.4.1'
  - velocloud_gateway
  - velocloud_orchestrator
  - netvisor_os < 7.1.0
  - netvisor_os = 7.1.0
  - simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware >= 3.1.5
  - simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware >= 3.1.5
patched:
  - linux_kernel 6.19.12
  - openshift_container_platform 4.21.14
  - nixos 25.11
  - netvisor_os 7.1.0
published: '2026-04-22'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T15:13:07.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31431'
references:
  - url: 'https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/29/23'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/29/25'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/29/26'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/15'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/17'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/20'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/30/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/15'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/17'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/22'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/23'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/01/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/15'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/17'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/19'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/20'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/21'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/23'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/25'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/02/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/13'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/03/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/13'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/27'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/28'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/29'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/31'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/04/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/06/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/07/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/07/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/08/13'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/18/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://copy.fail'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/260001'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:13565'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13566'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13577'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13578'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13681'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13690'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13727'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13729'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13734'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13811'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13862'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13885'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13887'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13932'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13936'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14097'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14112'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14137'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14165'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14230'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14301'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14339'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14773'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14926'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:15087'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:15976'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:15978'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16018'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16063'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16111'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16208'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16209'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16210'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19074'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19225'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:33486'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-31431'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigation
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460538'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-082556.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-265688.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-328642.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://github.com/theori-io/copy-fail-CVE-2026-31431'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31431.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://xint.io/blog/copy-fail-linux-distributions#the-fix-6'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-04-29T00:00:00+00:00'
epss: 0.03437
epssPercentile: 0.88529
kev: true
kevDateAdded: '2026-05-01'
kevDueDate: '2026-05-15'
kevRansomware: false
exploits:
  github: 321
  githubRepos:
    - 'https://github.com/theori-io/copy-fail-CVE-2026-31431'
    - 'https://github.com/tgies/copy-fail-c'
    - 'https://github.com/badsectorlabs/copyfail-go'
  metasploit:
    - exploit/linux/local/cve_2026_31431_copy_fail
  checkedAt: '2026-09-27T10:33:44.256Z'
ingestedAt: '2026-07-01T15:50:58.779Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

crypto: algif_aead - Revert to operating out-of-place

This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.

There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings.  Get rid of
all the complexity added for in-place operation and just copy the
AD directly.

## Affected

- `linux_kernel >= 4.14, < 5.10.254`
- `linux_kernel >= 5.11, < 5.15.204`
- `linux_kernel >= 5.16, < 6.1.170`
- `linux_kernel >= 6.2, < 6.6.137`
- `linux_kernel >= 6.7, < 6.12.85`
- `linux_kernel >= 6.13, < 6.18.22`
- `linux_kernel >= 6.19, < 6.19.12`
- `linux_kernel = 7.0`
- `openshift_container_platform >= 4.12, < 4.12.89`
- `openshift_container_platform >= 4.13, < 4.13.66`
- `openshift_container_platform >= 4.14, < 4.14.65`
- `openshift_container_platform >= 4.15, < 4.15.64`
- `openshift_container_platform >= 4.16, < 4.16.61`
- `openshift_container_platform >= 4.17, < 4.17.53`
- `openshift_container_platform >= 4.18, < 4.18.40`
- `openshift_container_platform >= 4.19, < 4.19.30`
- `openshift_container_platform >= 4.20, < 4.20.21`
- `openshift_container_platform >= 4.21, < 4.21.14`
- `openshift_container_platform = 4.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`
- `enterprise_linux_aus = 8.4`
- `enterprise_linux_aus = 8.6`
- `enterprise_linux_eus = 8.4`
- `enterprise_linux_eus = 9.4`
- `enterprise_linux_eus = 9.6`
- `enterprise_linux_eus = 10.0`
- `enterprise_linux_tus = 8.6`
- `enterprise_linux_tus = 8.8`
- `enterprise_linux_update_services_for_sap_solutions = 8.6`
- `enterprise_linux_update_services_for_sap_solutions = 8.8`
- `enterprise_linux_update_services_for_sap_solutions = 9.0`
- `enterprise_linux_update_services_for_sap_solutions = 9.2`
- `amazon_linux`
- `ubuntu_linux`
- `debian_linux = 11.0`
- `debian_linux = 12.0`
- `debian_linux = 13.0`
- `leap = 15.3`
- `leap = 15.4`
- `leap = 15.5`
- `leap = 15.6`
- `caas_platform = 4.0`
- `enterprise_storage = 6.0`
- `enterprise_storage = 7.0`
- `enterprise_storage = 7.1`
- `manager_proxy = 4.0`
- `manager_proxy = 4.1`
- `manager_proxy = 4.2`
- `manager_proxy = 4.3`
- `manager_retail_branch_server = 4.0`
- `manager_retail_branch_server = 4.1`
- `manager_retail_branch_server = 4.2`
- `manager_retail_branch_server = 4.3`
- `manager_server = 4.0`
- `manager_server = 4.1`
- `manager_server = 4.2`
- `manager_server = 4.3`
- `openstack_cloud = 9.0`
- `openstack_cloud_crowbar = 9.0`
- `basesystem_module = 15`
- `development_tools_module = 15`
- `legacy_module = 15`
- `linux_enterprise_desktop = 11`
- `linux_enterprise_desktop = 12`
- `linux_enterprise_desktop = 15`
- `linux_enterprise_high_availability_extension = 15`
- `linux_enterprise_high_availability_extension = 16.0`
- `linux_enterprise_high_performance_computing = 15.0`
- `linux_enterprise_live_patching = 12`
- `linux_enterprise_live_patching = 15`
- `linux_enterprise_micro = 5.0`
- `linux_enterprise_micro = 5.1`
- `linux_enterprise_micro = 5.2`
- `linux_enterprise_micro = 5.3`
- `linux_enterprise_micro = 5.4`
- `linux_enterprise_micro = 5.5`
- `linux_enterprise_real_time = 15.0`
- `linux_enterprise_server = 11`
- `linux_enterprise_server = 12`
- `linux_enterprise_server = 15`
- `linux_enterprise_server = 16.0`
- `linux_enterprise_server = 16.1`
- `linux_enterprise_workstation_extension = 15`
- `linux_micro = 6.0`
- `linux_micro = 6.1`
- `linux_micro = 6.2`
- `public_cloud_module = 15`
- `realtime_module = 15`
- `nixos < 25.11`
- `cloudvision_agni >= 2024.4.0, <= 2025.2.2`
- `cloudvision_portal >= 2024.2.0, <= 2026.1.0`
- `velocloud_edge >= 4.5.0, <= 6.4.1`
- `velocloud_gateway`
- `velocloud_orchestrator`
- `netvisor_os < 7.1.0`
- `netvisor_os = 7.1.0`
- `simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware >= 3.1.5`
- `simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware >= 3.1.5`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.12`
- `openshift_container_platform 4.21.14`
- `nixos 25.11`
- `netvisor_os 7.1.0`
