Evidence dossier

CVE-2026-31431

crypto: algif_aead - Revert to operating out-of-place

Exploited in the wild (CISA KEV since May 1, 2026). Linux reports CVSS 3.1 7.8. EPSS estimates 99.9% exploit likelihood as of Aug 6, 2026.

79.594.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

State
PUBLISHED
Published
Apr 22, 2026
Updated
Aug 5, 2026
Evidence coverage
85%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    Linux

    Record text: crypto: algif_aead - Revert to operating out-of-place

    Inspect raw assertion
    Field
    container
    Value
    crypto: algif_aead - Revert to operating out-of-place
    Original evidence ↗
  5. Source dateSource date omittedFirst observed by CASCA
    redhat-SADP

    Record text: kernel: crypto: algif_aead - Revert to operating out-of-place

    Inspect raw assertion
    Field
    container
    Value
    kernel: crypto: algif_aead - Revert to operating out-of-place
    Original evidence ↗
  6. Source dateSource date omittedFirst observed by CASCA
    siemens-SADP

    Record text: Container present

    Inspect raw assertion
    Field
    container
    Value
    Container present
    Original evidence ↗
  7. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.91% probability · 99.97th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999070000000; percentile 0.999670000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 1, 2026 · first observed Jul 19, 2026

Exploit likelihood99.91%

FIRST EPSS · score date Aug 6, 2026 · 100th percentile · first observed Aug 6, 2026

SeverityCVSS 7.8

Linux · CVSS 3.1 · first observed Aug 6, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
LinuxOriginal assertion
Record text

crypto: algif_aead - Revert to operating out-of-place

Inspect raw assertion
Field
container
Value
crypto: algif_aead - Revert to operating out-of-place
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
redhat-SADPSource-declared origin
Record text

kernel: crypto: algif_aead - Revert to operating out-of-place

Inspect raw assertion
Field
container
Value
kernel: crypto: algif_aead - Revert to operating out-of-place
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
siemens-SADPSource-declared origin
Record text

Container present

Inspect raw assertion
Field
container
Value
Container present
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.91% probability · 99.97th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999070000000; percentile 0.999670000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
203Underlying assertions
47Canonical products
199Target assertions
4Constraint assertions

Grouped from 17 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

100 scope groups

Linux · source assertedLinuxLinuxDirect source scope
Affected: 4.14Unaffected: 0 to before 4.14 (semver comparison)Unaffected: 5.10.254 through 5.10.* (semver comparison)Unaffected: 5.15.204 through 5.15.* (semver comparison)Unaffected: 6.1.170 through 6.1.* (semver comparison)Unaffected: 6.6.137 through 6.6.* (semver comparison)Unaffected: 6.12.85 through 6.12.* (semver comparison)Unaffected: 6.18.22 through 6.18.* (semver comparison)Unaffected: 6.19.12 through 6.19.* (semver comparison)Unaffected: 7.0 through * (original_commit_for_fix comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "4.14"}, {"status": "unaffected", "version": "0", "lessThan": "4.14", "versionType": "semver"}, {"status": "unaffected", "version": "5.10.254", "versionType": "semver", "lessThanOrEqual": "5.10.*"}, {"status": "unaffected", "version": "5.15.204", "versionType": "semver", "lessThanOrEqual": "5.15.*"}, {"status": "unaffected", "version": "6.1.170", "versionType": "semver", "lessThanOrEqual": "6.1.*"}, {"status": "unaffected", "version": "6.6.137", "versionType": "semver", "lessThanOrEqual": "6.6.*"}, {"status": "unaffected", "version": "6.12.85", "versionType": "semver", "lessThanOrEqual": "6.12.*"}, {"status": "unaffected", "version": "6.18.22", "versionType": "semver", "lessThanOrEqual": "6.18.*"}, {"status": "unaffected", "version": "6.19.12", "versionType": "semver", "lessThanOrEqual": "6.19.*"}, {"status": "unaffected", "version": "7.0", "versionType": "original_commit_for_fix", "lessThanOrEqual": "*"}]
Linux · source assertedLinuxLinuxDirect source scope
Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before 893d22e0135fa394db81df88697fba6032747667 (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before 19d43105a97be0810edbda875f2cd03f30dc130c (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before 961cfa271a918ad4ae452420e7c303149002875b (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before 3115af9644c342b356f3f07a4dd1c8905cd9a6fc (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before 8b88d99341f139e23bdeb1027a2a3ae10d341d82 (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before ce42ee423e58dffa5ec03524054c9d8bfd4f6237 (git comparison)Affected: 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 to before a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 (git comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "893d22e0135fa394db81df88697fba6032747667", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "19d43105a97be0810edbda875f2cd03f30dc130c", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "961cfa271a918ad4ae452420e7c303149002875b", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "3115af9644c342b356f3f07a4dd1c8905cd9a6fc", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "8b88d99341f139e23bdeb1027a2a3ae10d341d82", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "ce42ee423e58dffa5ec03524054c9d8bfd4f6237", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5", "versionType": "git"}]
redhat-SADP · source assertedRed HatNVIDIA for RHEL 10Direct source scope
Unaffected: 0:6.12.0-211.6.el10nv to before * (rpm comparison)Unaffected: 0:6.12.0-231.12.el10nv to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:6.12.0-211.6.el10nv", "lessThan": "*", "versionType": "rpm"}, {"status": "unaffected", "version": "0:6.12.0-231.12.el10nv", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 10Direct source scope
Unaffected: 0:6.12.0-124.55.1.el10_1 to before * (rpm comparison)Unaffected: 0:6.12.0-211.7.3.el10_2 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:6.12.0-124.55.1.el10_1", "lessThan": "*", "versionType": "rpm"}, {"status": "unaffected", "version": "0:6.12.0-211.7.3.el10_2", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 10.0 Extended Update SupportDirect source scope
Unaffected: 0:6.12.0-55.71.1.el10_0 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:6.12.0-55.71.1.el10_0", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 6Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 7Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 7Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8Direct source scope
Unaffected: 0:4.18.0-553.123.1.el8_10 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-553.123.1.el8_10", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8Direct source scope
Unaffected: 0:4.18.0-553.123.1.rt7.464.el8_10 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-553.123.1.rt7.464.el8_10", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportDirect source scope
Unaffected: 0:4.18.0-305.190.1.el8_4 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-305.190.1.el8_4", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnDirect source scope
Unaffected: 0:4.18.0-305.190.1.el8_4 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-305.190.1.el8_4", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportDirect source scope
Unaffected: 0:4.18.0-372.191.1.el8_6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-372.191.1.el8_6", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.6 Telecommunications Update ServiceDirect source scope
Unaffected: 0:4.18.0-372.191.1.el8_6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-372.191.1.el8_6", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.6 Update Services for SAP SolutionsDirect source scope
Unaffected: 0:4.18.0-372.191.1.el8_6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-372.191.1.el8_6", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.6 Update Services for SAP SolutionsDirect source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.8 Telecommunications Update ServiceDirect source scope
Unaffected: 0:4.18.0-477.139.1.el8_8 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-477.139.1.el8_8", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.8 Update Services for SAP SolutionsDirect source scope
Unaffected: 0:4.18.0-477.139.1.el8_8 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.18.0-477.139.1.el8_8", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 8.8 Update Services for SAP SolutionsDirect source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 9Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 9Direct source scope
Unaffected: 0:5.14.0-611.54.1.el9_7 to before * (rpm comparison)Unaffected: 0:5.14.0-687.5.3.el9_8 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:5.14.0-611.54.1.el9_7", "lessThan": "*", "versionType": "rpm"}, {"status": "unaffected", "version": "0:5.14.0-687.5.3.el9_8", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 9.0 Update Services for SAP SolutionsDirect source scope
Unaffected: 0:5.14.0-70.178.1.el9_0 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:5.14.0-70.178.1.el9_0", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 9.0 Update Services for SAP SolutionsDirect source scope
Unaffected: 0:5.14.0-70.178.1.rt21.250.el9_0 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:5.14.0-70.178.1.rt21.250.el9_0", "lessThan": "*", "versionType": "rpm"}]
redhat-SADP · source assertedRed HatRed Hat Enterprise Linux 9.0 Update Services for SAP SolutionsDirect source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

7.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
LinuxCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
redhat-SADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.