CVE-2026-31431 — Linux Kernel
CISA KEVAs of 2026-05-03, CVE-2026-31431 is a HIGH-severity vulnerability in Linux Kernel, CVSS v3.1 7.8, EPSS 3.9% (88.4th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-05-01), with a US federal remediation deadline of 2026-05-15. Threadlinqs Intelligence links 4 tracked threat campaigns to CVE-2026-31431, most recently “CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure”.
Last updated: 2026-05-03
What is CVE-2026-31431?
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place. This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
The record classifies CVE-2026-31431 under weakness class CWE-669. Its CVSS v3 base vector states that the flaw requires local access to the host, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 143 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 7.8 — HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS (FIRST)
- 3.9% probability of exploitation in the next 30 days, higher than 88.4% of all scored CVEs
- CISA KEV
- Listed since 2026-05-01, federal remediation deadline 2026-05-15
- Threadlinqs priority
- 9/10 — CISA KEV-listed, which Threadlinqs floors at 9
- Published
- 2026-04-22, last modified 2026-05-03
Is CVE-2026-31431 being exploited?
CISA added CVE-2026-31431 to the Known Exploited Vulnerabilities catalog on 2026-05-01, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2026-05-15 under BOD 22-01. It currently carries a trending score of 32 in the Threadlinqs vulnerability feed.
Affected products and versions
- Linux: Kernel
How to fix CVE-2026-31431
The record marks a vendor fix as available for CVE-2026-31431. Vendor advisory: https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8. Because CVE-2026-31431 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2026-05-15. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2026-31431
4 tracked threats in the Threadlinqs corpus reference CVE-2026-31431, either in the campaign’s CVE list or as an indicator on the campaign record.
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure — HIGH · 2026-08-03
- Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia (CVE-2026-43284/CVE-2026-43500/CVE-2026-46300), and CrackArmor AppArmor Flaws vs. Defense-in-Depth Mitigations — HIGH · 2026-05-29
- CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All Major Distributions — HIGH · 2026-05-08
- Linux Kernel 'Copy Fail' Local Privilege Escalation (CVE-2026-31431) — algif_aead 4-Byte Page Cache Write to setuid Root — HIGH · 2026-04-30
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
- git.kernel.org
- git.kernel.org (3115af9644c342b356f3f07a4dd1c8905cd9a6fc)
- git.kernel.org (893d22e0135fa394db81df88697fba6032747667)
- git.kernel.org (8b88d99341f139e23bdeb1027a2a3ae10d341d82)
- git.kernel.org (961cfa271a918ad4ae452420e7c303149002875b)
- git.kernel.org (a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5)
- git.kernel.org (ce42ee423e58dffa5ec03524054c9d8bfd4f6237)
- git.kernel.org (fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8)
- copy.fail
- websec.net
- access.redhat.com
- github.com
- lore.kernel.org
← all vulnerabilities · Markdown version · Threadlinqs Intelligence