← Security Alerts

CVE-2026-31431

Linux · published 2026-04-22

Source record Collected from the National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities

CISA lists this CVE as known exploited (added 2026-05-01).

Source: CISA KEV catalog (CC0 1.0).

Description

Description by kernel.org via the CVE Program.

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Filed by kernel.org; not a statement by Linux.

Status at the source

Affected products, as the source lists them

VendorProductVersions
LinuxLinux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before 893d22e0135fa394db81df88697fba6032747667: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before 19d43105a97be0810edbda875f2cd03f30dc130c: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before 961cfa271a918ad4ae452420e7c303149002875b: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before 3115af9644c342b356f3f07a4dd1c8905cd9a6fc: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before 8b88d99341f139e23bdeb1027a2a3ae10d341d82: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before ce42ee423e58dffa5ec03524054c9d8bfd4f6237: affected
72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – before a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5: affected
LinuxLinux4.14: affected
0 – before 4.14: unaffected
5.10.254 – 5.10.* and earlier: unaffected
5.15.204 – 5.15.* and earlier: unaffected
6.1.170 – 6.1.* and earlier: unaffected
6.6.137 – 6.6.* and earlier: unaffected
6.12.85 – 6.12.* and earlier: unaffected
6.18.22 – 6.18.* and earlier: unaffected
6.19.12 – 6.19.* and earlier: unaffected
7.0 – * and earlier: unaffected

Added by redhat-SADP (Authorized Data Publisher)

VendorProductVersions
Red HatNVIDIA for RHEL 100:6.12.0-211.6.el10nv – before *: unaffected
0:6.12.0-231.12.el10nv – before *: unaffected
Red HatRed Hat Enterprise Linux 100:6.12.0-124.55.1.el10_1 – before *: unaffected
0:6.12.0-211.7.3.el10_2 – before *: unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:6.12.0-55.71.1.el10_0 – before *: unaffected
Red HatRed Hat Enterprise Linux 80:4.18.0-553.123.1.rt7.464.el8_10 – before *: unaffected
Red HatRed Hat Enterprise Linux 80:4.18.0-553.123.1.el8_10 – before *: unaffected
Red HatRed Hat Enterprise Linux 8—
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:4.18.0-305.190.1.el8_4 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:4.18.0-305.190.1.el8_4 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:4.18.0-372.191.1.el8_6 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service0:4.18.0-372.191.1.el8_6 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions0:4.18.0-372.191.1.el8_6 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions—
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:4.18.0-477.139.1.el8_8 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:4.18.0-477.139.1.el8_8 – before *: unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions—
Red HatRed Hat Enterprise Linux 90:5.14.0-611.54.1.el9_7 – before *: unaffected
0:5.14.0-687.5.3.el9_8 – before *: unaffected
Red HatRed Hat Enterprise Linux 9—
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions0:5.14.0-70.178.1.el9_0 – before *: unaffected
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions0:5.14.0-70.178.1.rt21.250.el9_0 – before *: unaffected
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions—
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:5.14.0-284.169.1.el9_2 – before *: unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:5.14.0-284.169.1.rt14.454.el9_2 – before *: unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions—
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support0:5.14.0-427.124.1.el9_4 – before *: unaffected
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support—
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:5.14.0-570.112.1.el9_6 – before *: unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support—
Red HatRed Hat OpenShift Container Platform 4.12412.86.202605060316-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.13413.92.202605051442-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.14414.92.202605060243-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.15415.92.202605060220-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.16416.94.202605042300-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.17417.94.202605050021-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.18418.94.202605042017-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.194.19.9.6.202605042214-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.204.20.9.6.202605051409-0 – before *: unaffected
Red HatRed Hat OpenShift Container Platform 4.214.21.9.6.202605051105-0 – before *: unaffected
Red HatRed Hat Enterprise Linux 6—
Red HatRed Hat Enterprise Linux 7—
Red HatRed Hat Enterprise Linux 7—

Added by siemens-SADP (Authorized Data Publisher)

VendorProductVersions
SiemensSIMATIC AX Runtime Core Linux Common Debian0 – before *: affected
SiemensSIMATIC AX Runtime Core Linux Common Debian arm640 – before *: affected
SiemensSIMATIC AX Runtime Core Linux Platform Container Common Debian Development0 – before *: affected
SiemensSIMATIC AX Runtime Core Linux VMWare Development0 – before *: affected
SiemensSIMATIC CN 41000 – before V6.0: affected
SiemensSIMATIC HMI MTP1000 Unified Basic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1000 Unified Comfort Panel0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1000 Unified Comfort Panel hygienic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1000, Unified Comfort Panel neutral0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extension0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Unified Basic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Unified Comfort Panel0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Unified Comfort Panel hygienic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1200 Unified Comfort Panel neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extension0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Unified Comfort Panel0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Unified Comfort Panel hygienic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1500 Unified Comfort Panel neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extension0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Unified Comfort Panel0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Unified Comfort Panel hygienic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP1900 Unified Comfort Panel neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extension0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top)0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Unified Comfort Hygienic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Unified Comfort Panel0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP2200 Unified Comfort Panel neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP400 Unified Basic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP700 Unified Basic0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP700 Unified Comfort Panel0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC HMI MTP700, Unified Comfort Panel neutral design0 – before V21 Update 2 SR1: affected
SiemensSIMATIC IoT2050 Advanced0 – before *: affected

The source lists more products than DeSpy shows; see the source record.

Products named in NVD's CPE match criteria (48)
  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
  • cpe:2.3:o:amazon:amazon_linux:-:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:leap:15.3:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:caas_platform:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:enterprise_storage:6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:manager_proxy:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:manager_retail_branch_server:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:manager_server:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:openstack_cloud:9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:openstack_cloud_crowbar:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:basesystem_module:15:sp1:*:*:*:suse_linux_enterprise:*:*
  • cpe:2.3:o:suse:development_tools_module:15:sp1:*:*:*:suse_linux_enterprise:*:*
  • cpe:2.3:o:suse:legacy_module:15:sp7:*:*:*:suse_linux_enterprise:*:*
  • cpe:2.3:o:suse:linux_enterprise_desktop:11:sp4:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_high_availability_extension:15:sp4:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_high_performance_computing:15.0:sp1:*:*:-:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_live_patching:12:sp5:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_micro:5.0:*:*:*:*:-:*:*
  • cpe:2.3:o:suse:linux_enterprise_real_time:15.0:sp2:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:-:-:*:*
  • cpe:2.3:o:suse:linux_enterprise_workstation_extension:15:sp7:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_micro:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:public_cloud_module:15:sp6:*:*:*:suse_linux_enterprise:*:*
  • cpe:2.3:o:suse:realtime_module:15:sp3:*:*:*:suse_linux_enterprise:*:*
  • cpe:2.3:o:nixos:nixos:*:*:*:*:*:*:*:*
  • cpe:2.3:a:arista:cloudvision_agni:*:*:*:*:*:-:*:*
  • cpe:2.3:a:arista:cloudvision_portal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:arista:velocloud_edge:*:*:*:*:*:*:*:*
  • cpe:2.3:a:arista:velocloud_gateway:-:*:*:*:*:*:*:*
  • cpe:2.3:a:arista:velocloud_orchestrator:-:*:*:*:*:*:*:*
  • cpe:2.3:o:arista:netvisor_os:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_s7-1500_tm_mfp_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_cn_4100_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:a:siemens:simatic_ax_runtime:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_hmi_unified_comfort_panels_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_iot2050_advanced_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_ipc_ied-os:-:*:*:*:*:*:*:*

DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.

Scores, as their sources published them

DeSpy does not score records. These are the sources' own values.

Weaknesses

CWE-669, CWE-1288

Sources

References the source lists

The source lists more references.

Source dates: published 2026-04-22, last changed 2026-09-08. DeSpy's copy of this version is dated 2026-09-28.

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Scope, sources and licences →