Copy Fail - Linux Kernel Local Privilege Escalation via AF_ALG
CVE-2026-31431
Verified
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Severity
High
CVSS Score
7.8
Exploit Probability
3%
Affected Product
linux_kernel
Published Date
June 17, 2026
Template Author
ritikchaddha
CVE-2026-31431.yaml
7.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-31431
CWE ID:
cwe-787
References
Remediation Steps
Update the Linux kernel to a patched version. Upstream: 6.18.22+, 6.19.12+, 7.0+, LTS backports: 6.14.5+, 6.13.13+, 6.12.25+, 6.6.87+, 6.1.137+. If immediate patching is not possible, disable or blacklist the algif_aead kernel module