PT-2026-34274 · Linux+4 · Linux Kernel+4

·

CVE-2026-31431

·

Published

2026-03-23

·

Updated

2026-07-22

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0 Linux kernel versions prior to 6.19.12
Description A flaw exists in the algif aead cryptographic algorithm interface of the Linux kernel. The issue stems from an incorrect in-place operation during cryptographic processing where source and destination data mappings differ. A local attacker with low privileges can exploit this by splicing a readable file into an AF ALG socket and requesting an AEAD operation. This allows the attacker to perform a deterministic 4-byte write directly into the kernel's page cache, which is the in-memory copy of any file the user can read.
Because the page cache is shared between containers and the host, this can be used to corrupt sensitive system files (such as /usr/bin/su or /usr/sbin/ipset) in memory without altering the file on disk. This enables the attacker to bypass file integrity checks and escalate privileges to root. In Kubernetes environments, this can lead to a container escape where an unprivileged container achieves node-level code execution by corrupting a binary shared with a privileged DaemonSet, such as kube-proxy.
Recommendations Update the Linux kernel to version 7.0 or 6.19.12 or newer. As a temporary mitigation in Kubernetes environments, restrict pod scheduling to prevent untrusted workloads from landing on nodes running privileged DaemonSets that share base images.

Exploit

Fix

DoS

LPE

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:13565
ALSA-2026:13566
ALSA-2026:13577
ALSA-2026:13578
ALSA-2026:19074
ALSA-2026:19225
ALSA-2026:A001
ALSA-2026:A002
ALSA-2026:A003
BDU:2026-06123
BDU:2026-09232
CVE-2026-31431
ECHO-41E7-B14A-B4FB
GHSA-M38G-VWW2-MVGX
OESA-2026-2172
OESA-2026-2173
OESA-2026-2174
OESA-2026-2175
OESA-2026-2176
OPENSUSE-SU-2026:10734-1
OPENSUSE-SU-2026:20665-1
RHSA-2026:13565
RHSA-2026:13566
RHSA-2026:13577
RHSA-2026:13578
RHSA-2026:13681
RHSA-2026:13734
RHSA-2026:13887
RHSA-2026:13932
RHSA-2026:13936
RHSA-2026:14137
RHSA-2026:14165
RHSA-2026:14230
RHSA-2026:14301
RHSA-2026:14339
RHSA-2026:14926
RHSA-2026:15976
RHSA-2026:15978
RHSA-2026:16018
RHSA-2026:16063
RHSA-2026:16111
RHSA-2026:16208
RHSA-2026:16209
RHSA-2026:16210
RHSA-2026:33486
SUSE-SU-2026:1669-1
SUSE-SU-2026:1670-1
SUSE-SU-2026:1671-1
SUSE-SU-2026:1671-2
SUSE-SU-2026:1672-1
SUSE-SU-2026:1674-1
SUSE-SU-2026:1675-1
SUSE-SU-2026:1676-1
SUSE-SU-2026:1677-1
SUSE-SU-2026:1678-1
SUSE-SU-2026:1684-1
SUSE-SU-2026:1686-1
SUSE-SU-2026:1689-1
SUSE-SU-2026:1690-1
SUSE-SU-2026:1691-1
SUSE-SU-2026:1694-1
SUSE-SU-2026:1698-1
SUSE-SU-2026:1706-1
SUSE-SU-2026:1708-1
SUSE-SU-2026:1710-1
SUSE-SU-2026:1718-1
SUSE-SU-2026:1724-1
SUSE-SU-2026:1725-1
SUSE-SU-2026:1726-1
SUSE-SU-2026:1728-1
SUSE-SU-2026:1733-1
SUSE-SU-2026:1735-1
SUSE-SU-2026:1736-1
SUSE-SU-2026:1765-1
SUSE-SU-2026:1767-1
SUSE-SU-2026:1768-1
SUSE-SU-2026:1770-1
SUSE-SU-2026:1771-1
SUSE-SU-2026:1773-1
SUSE-SU-2026:1775-1
SUSE-SU-2026:1776-1
SUSE-SU-2026:1780-1
SUSE-SU-2026:1781-1
SUSE-SU-2026:1786-1
SUSE-SU-2026:1787-1
SUSE-SU-2026:1790-1
SUSE-SU-2026:1791-1
SUSE-SU-2026:1792-1
SUSE-SU-2026:1793-1
SUSE-SU-2026:1798-1
SUSE-SU-2026:1801-1
SUSE-SU-2026:1802-1
SUSE-SU-2026:1804-1
SUSE-SU-2026:21421-1
SUSE-SU-2026:21439-1
SUSE-SU-2026:21442-1
SUSE-SU-2026:21443-1
SUSE-SU-2026:21453-1
SUSE-SU-2026:21454-1
SUSE-SU-2026:21460-1
SUSE-SU-2026:21463-1
SUSE-SU-2026:21467-1
SUSE-SU-2026:21468-1
SUSE-SU-2026:21469-1
SUSE-SU-2026:21470-1
SUSE-SU-2026:21471-1
SUSE-SU-2026:21472-1
SUSE-SU-2026:21473-1
SUSE-SU-2026:21474-1
SUSE-SU-2026:21475-1
SUSE-SU-2026:21476-1
SUSE-SU-2026:21477-1
SUSE-SU-2026:21478-1
SUSE-SU-2026:21479-1
SUSE-SU-2026:21480-1
SUSE-SU-2026:21481-1
SUSE-SU-2026:21482-1
SUSE-SU-2026:21483-1
SUSE-SU-2026:21484-1
SUSE-SU-2026:21485-1
SUSE-SU-2026:21486-1
SUSE-SU-2026:21487-1
SUSE-SU-2026:21488-1
SUSE-SU-2026:21489-1
SUSE-SU-2026:21491-1
SUSE-SU-2026:21494-1
SUSE-SU-2026:21495-1
SUSE-SU-2026:21496-1
SUSE-SU-2026:21497-1
SUSE-SU-2026:21498-1
SUSE-SU-2026:21499-1
SUSE-SU-2026:21500-1
SUSE-SU-2026:21501-1
SUSE-SU-2026:21502-1
SUSE-SU-2026:21503-1
SUSE-SU-2026:21504-1
SUSE-SU-2026:21505-1
SUSE-SU-2026:21506-1
SUSE-SU-2026:21507-1
SUSE-SU-2026:21508-1
SUSE-SU-2026:21509-1
SUSE-SU-2026:21510-1
SUSE-SU-2026:21511-1
SUSE-SU-2026:21512-1
SUSE-SU-2026:21513-1
SUSE-SU-2026:21514-1
SUSE-SU-2026:21515-1
SUSE-SU-2026:21516-1
SUSE-SU-2026:21517-1
SUSE-SU-2026:21519-1
SUSE-SU-2026:21520-1
SUSE-SU-2026:21521-1
SUSE-SU-2026:21522-1
SUSE-SU-2026:21523-1
SUSE-SU-2026:21524-1
SUSE-SU-2026:21525-1
SUSE-SU-2026:21526-1
SUSE-SU-2026:21527-1
SUSE-SU-2026:21528-1
SUSE-SU-2026:21529-1
SUSE-SU-2026:21530-1
SUSE-SU-2026:21531-1
SUSE-SU-2026:21532-1
SUSE-SU-2026:21533-1
SUSE-SU-2026:21554-1
SUSE-SU-2026:21555-1
SUSE-SU-2026:21556-1
SUSE-SU-2026:21557-1
SUSE-SU-2026:21558-1
SUSE-SU-2026:21562-1
SUSE-SU-2026:21563-1
SUSE-SU-2026:21591-1
SUSE-SU-2026:21598-1
USN-8226-1
USN-8226-2
USN-8277-1
USN-8277-2
USN-8278-1
USN-8278-2
USN-8279-1
USN-8279-2
USN-8279-3
USN-8280-1
USN-8280-2
USN-8280-3
USN-8281-1
USN-8281-2
USN-8289-1
USN-8289-2
USN-8305-1
USN-8305-2
USN-8310-1
USN-8350-1
USN-8351-1
USN-8374-1
USN-8391-1
USN-8392-1
USN-8393-1
USN-8426-1
USN-8426-2
USN-8440-1
USN-8441-1
USN-8462-1
USN-8499-1
USN-8528-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu