Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31431

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 7.8
EPSS Высокий

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

A flaw was found in the Linux kernel's algif_aead cryptographic algorithm interface. An incorrect in-place operation causes source and destination data mappings to differ during cryptographic processing. A low-privileged local attacker can exploit this flaw to corrupt the contents of sensitive system files and escalate to root privileges.

Отчет

This issue is classified as Important, rather than Critical severity, because exploitation requires local access to the system. A low-privileged local attacker can exploit this flaw in the Linux kernel's cryptographic interface to gain root privileges by overwriting sensitive system files. Exploitation does not require user interaction, potentially resulting in full compromise of confidentiality, integrity, and availability.

Меры по смягчению последствий

See the security bulletin for a detailed mitigation procedure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
NVIDIA for RHEL 10kernelFixedRHSA-2026:1492607.05.2026
Red Hat Enterprise Linux 10kernelFixedRHSA-2026:1356604.05.2026
Red Hat Enterprise Linux 10kernelFixedRHSA-2026:1907419.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportkernelFixedRHSA-2026:1388705.05.2026
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2026:1357805.05.2026
Red Hat Enterprise Linux 8kernelFixedRHSA-2026:1357705.05.2026
Red Hat Enterprise Linux 8kpatch-patchFixedRHSA-2026:1597611.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1288
https://bugzilla.redhat.com/show_bug.cgi?id=2460538kernel: crypto: algif_aead - Revert to operating out-of-place

EPSS

Процентиль: 99%
0.75521
Высокий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVSS3: 7.8
nvd
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

msrc
около 2 месяцев назад

crypto: algif_aead - Revert to operating out-of-place

CVSS3: 7.8
debian
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: c ...

suse-cvrf
около 2 месяцев назад

Security update for the Linux Kernel

EPSS

Процентиль: 99%
0.75521
Высокий

7.8 High

CVSS3