CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2026-05-01. EPSS: 3.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Affected products

  • Amazon Amazon Linux: affected versions not specified
  • Arista Cloudvision Agni: from 2024.4.0, up to and including 2025.2.2
  • Arista Cloudvision Portal: from 2024.2.0, up to and including 2026.1.0
  • Arista Netvisor OS: before 7.1.0 (fixed in 7.1.0); version 7.1.0 only
  • Arista VeloCloud Edge: from 4.5.0, up to and including 6.4.1
  • Arista VeloCloud Gateway: affected versions not specified
  • Arista VeloCloud Orchestrator: affected versions not specified
  • Canonical Ubuntu Linux: affected versions not specified; version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only; version 22.04 only; …
  • Debian Debian Linux: version 11.0 only; version 12.0 only; version 13.0 only
  • Linux Linux Kernel: from 4.14, before 5.10.254 (fixed in 5.10.254); from 5.11, before 5.15.204 (fixed in 5.15.204); from 5.16, before 6.1.170 (fixed in 6.1.170); from 6.2, before 6.6.137 (fixed in 6.6.137); from 6.7, before 6.12.85 (fixed in 6.12.85); from 6.13, before 6.18.22 (fixed in 6.18.22); …
  • Nixos Nixos: before 25.11 (fixed in 25.11)
  • Opensuse Leap: version 15.3 only; version 15.4 only; version 15.5 only; version 15.6 only
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Red Hat Enterprise Linux Aus: version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Eus: version 8.4 only; version 9.4 only; version 9.6 only; version 10.0 only
  • Red Hat Enterprise Linux Tus: version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Openshift Container Platform: from 4.12, before 4.12.89 (fixed in 4.12.89); from 4.13, before 4.13.66 (fixed in 4.13.66); from 4.14, before 4.14.65 (fixed in 4.14.65); from 4.15, before 4.15.64 (fixed in 4.15.64); from 4.16, before 4.16.61 (fixed in 4.16.61); from 4.17, before 4.17.53 (fixed in 4.17.53); …
  • Siemens SIMATIC Ax Runtime: affected versions not specified
  • Siemens SIMATIC Cn 4100 Firmware: before 6.0 (fixed in 6.0)
  • Siemens SIMATIC HMI Unified Comfort Panels Firmware: before 21.0 (fixed in 21.0); version 21.0 only
  • Siemens SIMATIC IOT2050 Advanced Firmware: affected versions not specified
  • Siemens SIMATIC Ipc Ied-OS: affected versions not specified
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp Firmware: from 3.1.5
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp Firmware: from 3.1.5
  • and 23 more

Published 2026-04-22. Last modified 2026-09-08.