VDB
RHSA-2026%3A13811
RHSA-2026%3A13811
PUBLISHED
CVSS 7.800000190734863 HIGH
A flaw was found in the Linux kernel's algif_aead cryptographic algorithm interface. An incorrect in-place operation causes source and destination data mappings to differ during cryptographic processing. A low-privileged local attacker can exploit this flaw to corrupt the contents of sensitive system files and escalate to root privileges.
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-s390x-4.21.9.6.202605051105-0 as a component of Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202605051105-0, 4.21.9.6.202605051105-0, rhcos-s390x-4.21.9.6.202605051105-0 |
| Red Hat | rhcos-ppc64le-4.21.9.6.202605051105-0 as a component of Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202605051105-0, 4.21.9.6.202605051105-0, rhcos-ppc64le-4.21.9.6.202605051105-0 |
| Red Hat | rhcos-x86_64-4.21.9.6.202605051105-0 as a component of Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202605051105-0, 4.21.9.6.202605051105-0, rhcos-x86_64-4.21.9.6.202605051105-0 |
| Red Hat | rhcos-aarch64-4.21.9.6.202605051105-0 as a component of Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202605051105-0, 4.21.9.6.202605051105-0, rhcos-aarch64-4.21.9.6.202605051105-0 |
Timeline
- Apr 30, 2026 PoC Published
- May 6, 2026 CVE Published
- May 6, 2026 Distribution Patch
- May 6, 2026 Distribution Patch
- May 6, 2026 Security Advisory
- May 6, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:13811 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460538 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13811.json advisory
- https://access.redhat.com/security/cve/CVE-2026-31431 advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2026-02 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-31431 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-31431 advisory
- https://access.redhat.com/articles/7141989 advisory
- https://access.redhat.com/solutions/7141931 advisory
- https://access.redhat.com/solutions/7141979 advisory
- https://access.redhat.com/solutions/7141990 advisory
- https://access.redhat.com/solutions/7141996 advisory
- https://access.redhat.com/solutions/7142032 advisory
- https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/managing_monitoring_and_updating_the_kernel/configuring-kernel-command-line-parameters_managing-monitoring-and-updating-the-kernel advisory
- https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/T advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit
- https://access.redhat.com/security/vulnerabilities/RHSB-2026-002 advisory