CISA KEV · catalog date May 1, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Exploited in the wild (CISA KEV since May 1, 2026). Linux reports CVSS 3.1 7.8. EPSS estimates 99.9% exploit likelihood as of Aug 6, 2026.
As of Aug 27, 2026
Normalized restatement
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
- State
- PUBLISHED
- Published
- Apr 22, 2026
- Updated
- Aug 5, 2026
- Evidence coverage
- 85%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCALinuxOriginal evidence ↗
Record text: crypto: algif_aead - Revert to operating out-of-place
Inspect raw assertion
- Field
container- Value
- crypto: algif_aead - Revert to operating out-of-place
- Source dateSource date omittedFirst observed by CASCAredhat-SADPOriginal evidence ↗
Record text: kernel: crypto: algif_aead - Revert to operating out-of-place
Inspect raw assertion
- Field
container- Value
- kernel: crypto: algif_aead - Revert to operating out-of-place
- Source dateSource date omittedFirst observed by CASCAsiemens-SADPOriginal evidence ↗
Record text: Container present
Inspect raw assertion
- Field
container- Value
- Container present
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.91% probability · 99.97th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999070000000; percentile 0.999670000000
FIRST EPSS · score date Aug 6, 2026 · 100th percentile · first observed Aug 6, 2026
Linux · CVSS 3.1 · first observed Aug 6, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
crypto: algif_aead - Revert to operating out-of-place
Inspect raw assertion
- Field
container- Value
- crypto: algif_aead - Revert to operating out-of-place
kernel: crypto: algif_aead - Revert to operating out-of-place
Inspect raw assertion
- Field
container- Value
- kernel: crypto: algif_aead - Revert to operating out-of-place
Container present
Inspect raw assertion
- Field
container- Value
- Container present
99.91% probability · 99.97th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999070000000; percentile 0.999670000000
Applicability
Cited product scope
Grouped from 17 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
100 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.14"}, {"status": "unaffected", "version": "0", "lessThan": "4.14", "versionType": "semver"}, {"status": "unaffected", "version": "5.10.254", "versionType": "semver", "lessThanOrEqual": "5.10.*"}, {"status": "unaffected", "version": "5.15.204", "versionType": "semver", "lessThanOrEqual": "5.15.*"}, {"status": "unaffected", "version": "6.1.170", "versionType": "semver", "lessThanOrEqual": "6.1.*"}, {"status": "unaffected", "version": "6.6.137", "versionType": "semver", "lessThanOrEqual": "6.6.*"}, {"status": "unaffected", "version": "6.12.85", "versionType": "semver", "lessThanOrEqual": "6.12.*"}, {"status": "unaffected", "version": "6.18.22", "versionType": "semver", "lessThanOrEqual": "6.18.*"}, {"status": "unaffected", "version": "6.19.12", "versionType": "semver", "lessThanOrEqual": "6.19.*"}, {"status": "unaffected", "version": "7.0", "versionType": "original_commit_for_fix", "lessThanOrEqual": "*"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "893d22e0135fa394db81df88697fba6032747667", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "19d43105a97be0810edbda875f2cd03f30dc130c", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "961cfa271a918ad4ae452420e7c303149002875b", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "3115af9644c342b356f3f07a4dd1c8905cd9a6fc", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "8b88d99341f139e23bdeb1027a2a3ae10d341d82", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "ce42ee423e58dffa5ec03524054c9d8bfd4f6237", "versionType": "git"}, {"status": "affected", "version": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7", "lessThan": "a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5", "versionType": "git"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:6.12.0-211.6.el10nv", "lessThan": "*", "versionType": "rpm"}, {"status": "unaffected", "version": "0:6.12.0-231.12.el10nv", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:6.12.0-124.55.1.el10_1", "lessThan": "*", "versionType": "rpm"}, {"status": "unaffected", "version": "0:6.12.0-211.7.3.el10_2", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:6.12.0-55.71.1.el10_0", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-553.123.1.el8_10", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-553.123.1.rt7.464.el8_10", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-305.190.1.el8_4", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-305.190.1.el8_4", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-372.191.1.el8_6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-372.191.1.el8_6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-372.191.1.el8_6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-477.139.1.el8_8", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.18.0-477.139.1.el8_8", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:5.14.0-611.54.1.el9_7", "lessThan": "*", "versionType": "rpm"}, {"status": "unaffected", "version": "0:5.14.0-687.5.3.el9_8", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:5.14.0-70.178.1.el9_0", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:5.14.0-70.178.1.rt21.250.el9_0", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.