CVE-2026-31431 is a high-severity Linux kernel vulnerability in algif_aead. Actively exploited and affects various distributions. Patch immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| linux_kernel | 4.14 | 5.10.254 | vulnerable |
| linux_kernel | 5.11 | 5.15.204 | vulnerable |
| linux_kernel | 5.16 | 6.1.170 | vulnerable |
| linux_kernel | 6.2 | 6.6.137 | vulnerable |
| linux_kernel | 6.7 | 6.12.85 | vulnerable |
| linux_kernel | 6.13 | 6.18.22 | vulnerable |
| linux_kernel | 6.19 | 6.19.12 | vulnerable |
| linux_kernel | 7.0 | 7.0 | vulnerable |
| linux_kernel | 7.0 | 7.0 | vulnerable |
| linux_kernel | 7.0 | 7.0 | vulnerable |
| linux_kernel | 7.0 | 7.0 | vulnerable |
| linux_kernel | 7.0 | 7.0 | vulnerable |
| linux_kernel | 7.0 | 7.0 | vulnerable |
| openshift_container_platform | 4.12 | 4.12.89 | vulnerable |
| openshift_container_platform | 4.13 | 4.13.66 | vulnerable |
| openshift_container_platform | 4.14 | 4.14.65 | vulnerable |
| openshift_container_platform | 4.15 | 4.15.64 | vulnerable |
| openshift_container_platform | 4.16 | 4.16.61 | vulnerable |
| openshift_container_platform | 4.17 | 4.17.53 | vulnerable |
| openshift_container_platform | 4.18 | 4.18.40 | vulnerable |
| openshift_container_platform | 4.19 | 4.19.30 | vulnerable |
| openshift_container_platform | 4.20 | 4.20.21 | vulnerable |
| openshift_container_platform | 4.21 | 4.21.14 | vulnerable |
| openshift_container_platform | 4.0 | 4.0 | vulnerable |
| enterprise_linux | 8.0 | 8.0 | vulnerable |
| enterprise_linux | 9.0 | 9.0 | vulnerable |
| enterprise_linux | 10.0 | 10.0 | vulnerable |
| enterprise_linux_aus | 8.4 | 8.4 | vulnerable |
| enterprise_linux_aus | 8.6 | 8.6 | vulnerable |
| enterprise_linux_eus | 8.4 | 8.4 | vulnerable |
| enterprise_linux_eus | 9.4 | 9.4 | vulnerable |
| enterprise_linux_eus | 9.6 | 9.6 | vulnerable |
| enterprise_linux_eus | 10.0 | 10.0 | vulnerable |
| enterprise_linux_tus | 8.6 | 8.6 | vulnerable |
| enterprise_linux_tus | 8.8 | 8.8 | vulnerable |
| enterprise_linux_update_services_for_sap_solutions | 8.6 | 8.6 | vulnerable |
| enterprise_linux_update_services_for_sap_solutions | 8.8 | 8.8 | vulnerable |
| enterprise_linux_update_services_for_sap_solutions | 9.0 | 9.0 | vulnerable |
| enterprise_linux_update_services_for_sap_solutions | 9.2 | 9.2 | vulnerable |
| amazon_linux | - | - | vulnerable |
| ubuntu_linux | - | - | vulnerable |
| debian_linux | 11.0 | 11.0 | vulnerable |
| debian_linux | 12.0 | 12.0 | vulnerable |
| debian_linux | 13.0 | 13.0 | vulnerable |
| leap | 15.3 | 15.3 | vulnerable |
| leap | 15.4 | 15.4 | vulnerable |
| leap | 15.5 | 15.5 | vulnerable |
| leap | 15.6 | 15.6 | vulnerable |
| caas_platform | 4.0 | 4.0 | vulnerable |
| enterprise_storage | 6.0 | 6.0 | vulnerable |
| enterprise_storage | 7.0 | 7.0 | vulnerable |
| enterprise_storage | 7.1 | 7.1 | vulnerable |
| manager_proxy | 4.0 | 4.0 | vulnerable |
| manager_proxy | 4.1 | 4.1 | vulnerable |
| manager_proxy | 4.2 | 4.2 | vulnerable |
| manager_proxy | 4.3 | 4.3 | vulnerable |
| manager_retail_branch_server | 4.0 | 4.0 | vulnerable |
| manager_retail_branch_server | 4.1 | 4.1 | vulnerable |
| manager_retail_branch_server | 4.2 | 4.2 | vulnerable |
| manager_retail_branch_server | 4.3 | 4.3 | vulnerable |
| manager_server | 4.0 | 4.0 | vulnerable |
| manager_server | 4.1 | 4.1 | vulnerable |
| manager_server | 4.2 | 4.2 | vulnerable |
| manager_server | 4.3 | 4.3 | vulnerable |
| openstack_cloud | 9.0 | 9.0 | vulnerable |
| openstack_cloud_crowbar | 9.0 | 9.0 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| basesystem_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| development_tools_module | 15 | 15 | vulnerable |
| legacy_module | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 11 | 11 | vulnerable |
| linux_enterprise_desktop | 12 | 12 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_desktop | 15 | 15 | vulnerable |
| linux_enterprise_high_availability_extension | 15 | 15 | vulnerable |
| linux_enterprise_high_availability_extension | 15 | 15 | vulnerable |
| linux_enterprise_high_availability_extension | 15 | 15 | vulnerable |
| linux_enterprise_high_availability_extension | 16.0 | 16.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_high_performance_computing | 15.0 | 15.0 | vulnerable |
| linux_enterprise_live_patching | 12 | 12 | vulnerable |
| linux_enterprise_live_patching | 15 | 15 | vulnerable |
| linux_enterprise_live_patching | 15 | 15 | vulnerable |
| linux_enterprise_live_patching | 15 | 15 | vulnerable |
| linux_enterprise_live_patching | 15 | 15 | vulnerable |
| linux_enterprise_micro | 5.0 | 5.0 | vulnerable |
| linux_enterprise_micro | 5.1 | 5.1 | vulnerable |
| linux_enterprise_micro | 5.2 | 5.2 | vulnerable |
| linux_enterprise_micro | 5.2 | 5.2 | vulnerable |
| linux_enterprise_micro | 5.3 | 5.3 | vulnerable |
| linux_enterprise_micro | 5.3 | 5.3 | vulnerable |
| linux_enterprise_micro | 5.4 | 5.4 | vulnerable |
| linux_enterprise_micro | 5.4 | 5.4 | vulnerable |
| linux_enterprise_micro | 5.5 | 5.5 | vulnerable |
| linux_enterprise_real_time | 15.0 | 15.0 | vulnerable |
| linux_enterprise_real_time | 15.0 | 15.0 | vulnerable |
| linux_enterprise_real_time | 15.0 | 15.0 | vulnerable |
| linux_enterprise_real_time | 15.0 | 15.0 | vulnerable |
| linux_enterprise_real_time | 15.0 | 15.0 | vulnerable |
| linux_enterprise_real_time | 15.0 | 15.0 | vulnerable |
| linux_enterprise_server | 11 | 11 | vulnerable |
| linux_enterprise_server | 11 | 11 | vulnerable |
| linux_enterprise_server | 11 | 11 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 12 | 12 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 15 | 15 | vulnerable |
| linux_enterprise_server | 16.0 | 16.0 | vulnerable |
| linux_enterprise_server | 16.0 | 16.0 | vulnerable |
| linux_enterprise_server | 16.1 | 16.1 | vulnerable |
| linux_enterprise_server | 16.1 | 16.1 | vulnerable |
| linux_enterprise_workstation_extension | 15 | 15 | vulnerable |
| linux_micro | 6.0 | 6.0 | vulnerable |
| linux_micro | 6.1 | 6.1 | vulnerable |
| linux_micro | 6.2 | 6.2 | vulnerable |
| public_cloud_module | 15 | 15 | vulnerable |
| public_cloud_module | 15 | 15 | vulnerable |
| realtime_module | 15 | 15 | vulnerable |
| realtime_module | 15 | 15 | vulnerable |
| realtime_module | 15 | 15 | vulnerable |
| realtime_module | 15 | 15 | vulnerable |
| realtime_module | 15 | 15 | vulnerable |
| nixos | * | 25.11 | vulnerable |
| cloudvision_agni | 2024.4.0 | 2025.2.2 | vulnerable |
| cloudvision_portal | 2024.2.0 | 2026.1.0 | vulnerable |
| velocloud_edge | 4.5.0 | 6.4.1 | vulnerable |
| velocloud_gateway | - | - | vulnerable |
| velocloud_orchestrator | - | - | vulnerable |
| netvisor_os | * | 7.1.0 | vulnerable |
| netvisor_os | 7.1.0 | 7.1.0 | vulnerable |
| netvisor_os | 7.1.0 | 7.1.0 | vulnerable |
| simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware | 3.1.5 | * | vulnerable |
| simatic_s7-1500_cpu_1518-4_pn\/dp_mfp | - | - | unaffected |
| simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware | 3.1.5 | * | vulnerable |
| simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp | - | - | unaffected |
| siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware | 3.1.5 | * | vulnerable |
| siplus_s7-1500_cpu_1518-4_pn\/dp_mfp | - | - | unaffected |
| simatic_s7-1500_tm_mfp_firmware | - | - | vulnerable |
| simatic_s7-1500_tm_mfp | - | - | unaffected |
| ubuntu_linux | 14.04 | 14.04 | vulnerable |
| ubuntu_linux | 16.04 | 16.04 | vulnerable |
| ubuntu_linux | 18.04 | 18.04 | vulnerable |
| ubuntu_linux | 20.04 | 20.04 | vulnerable |
| ubuntu_linux | 22.04 | 22.04 | vulnerable |
| ubuntu_linux | 24.04 | 24.04 | vulnerable |
| ubuntu_linux | 25.10 | 25.10 | vulnerable |
| simatic_cn_4100_firmware | * | 6.0 | vulnerable |
| simatic_cn_4100 | - | - | unaffected |
| simatic_ax_runtime | - | - | vulnerable |
| simatic_hmi_unified_comfort_panels_firmware | * | 21.0 | vulnerable |
| simatic_hmi_unified_comfort_panels_firmware | 21.0 | 21.0 | vulnerable |
| simatic_hmi_unified_comfort_panels_firmware | 21.0 | 21.0 | vulnerable |
| simatic_hmi_unified_comfort_panels_firmware | 21.0 | 21.0 | vulnerable |
| simatic_hmi_mtp1000 | - | - | unaffected |
| simatic_hmi_mtp1200 | - | - | unaffected |
| simatic_hmi_mtp1500 | - | - | unaffected |
| simatic_hmi_mtp1900 | - | - | unaffected |
| simatic_hmi_mtp2200 | - | - | unaffected |
| simatic_hmi_mtp700 | - | - | unaffected |
| simatic_iot2050_advanced_firmware | - | - | vulnerable |
| simatic_iot2050_advanced | - | - | unaffected |
| simatic_ipc_ied-os | - | - | vulnerable |
Consult your specific Linux distribution's security advisories (such as Red Hat, Ubuntu, Debian, or SUSE) and apply the latest kernel security updates that include the fix for the algif_aead regression.
Ensure your Linux kernel is updated to a non-vulnerable version. Fixed versions include 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, or later, depending on your specific stable release branch.
As this is a local attack vector, enforce the principle of least privilege (PoLP) to limit shell access. Additionally, consider using Linux Security Modules (LSMs) like SELinux or AppArmor to restrict access to AF_ALG sockets to only authorized services.
Audit system logs for kernel 'oops' messages or panics related to crypto API mappings. Use tools like auditd to monitor for suspicious calls to the AF_ALG address family from unauthorized user accounts.
Practical detection involves monitoring for kernel instability or memory corruption indicators. Watch for system logs containing 'algif_aead' or 'crypto' related stack traces. Implement auditd rules to log AF_ALG socket creation and bind operations. Security teams should prioritize EDR signatures that detect local privilege escalation patterns or unusual kernel memory access. Network-based detection is less effective here due to the local nature of the attack vector, so focus on host-based telemetry and integrity monitoring.
Experience superior visibility and a simpler approach to cyber risk management