QSearchQSearch

CVE-2026-31431

7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly r...

Published: 2026-04-22 · Last updated: 2026-05-21

Severity and scoring

CVSS
7.8 HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-669

Affected products

VendorProduct
amazonamazon_linux, basesystem_module, caas_platform
aristaamazon_linux, basesystem_module, caas_platform
canonicalamazon_linux, basesystem_module, caas_platform
debianamazon_linux, basesystem_module, caas_platform
linuxamazon_linux, basesystem_module, caas_platform
nixosamazon_linux, basesystem_module, caas_platform
opensuseamazon_linux, basesystem_module, caas_platform
redhatamazon_linux, basesystem_module, caas_platform
siemensamazon_linux, basesystem_module, caas_platform
suseamazon_linux, basesystem_module, caas_platform
vmwareamazon_linux, basesystem_module, caas_platform

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-41851 Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) atta... (5.3 MEDIUM)
  • CVE-2026-41850 Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service... (7.5 HIGH)
  • CVE-2026-41849 An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL) (7.5 HIGH)
  • CVE-2026-41843 Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources (5.9 MEDIUM)
  • CVE-2026-41842 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources (7.5 HIGH)

Same CWE

  • CVE-2026-44917 OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via ... (4.9 MEDIUM)
  • CVE-2026-46447 OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info (5.8 MEDIUM)
  • CVE-2026-48847 Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache sessio... (3.7 LOW)
  • CVE-2026-48846 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var(... (6.5 MEDIUM)
  • CVE-2026-48845 In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to l... (6.5 MEDIUM)