crypto: algif_aead - Revert to operating out-of-place
Summary
| CVE | CVE-2026-31431 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-22 09:16:21 UTC |
| Updated | 2026-04-22 09:16:21 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings. Get rid of
all the complexity added for in-place operation and just copy the
AD directly. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 git |
Not specified |
| CNA |
Linux |
Linux |
affected 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 ce42ee423e58dffa5ec03524054c9d8bfd4f6237 git |
Not specified |
| CNA |
Linux |
Linux |
affected 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.14 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.14 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.22 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.19.12 6.19.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.