Database/Kernel, userspace & hypervisor
Linux kernel (crypto algif_aead): Incorrect resource transfer between spheres in algif_aead (reverted to out-of-place
CVSS 7.8CVE-2026-31431Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Incorrect resource transfer between spheres in algif_aead (reverted to out-of-place operation) - local privilege escalation, actively exploited [KEV]
Who can reach it
Any tenant process in a container (AF_ALG socket access)
What to do
Livepatchable; otherwise drain + reboot. Compensating control: block AF_ALG in the default container seccomp profile
References
Related entries
- Linux kernel (drivers/vfio/pci): The error path of the vfio-pci dma-buf export falls through the whole unwind chainCVE-2026-31468 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
- Linux kernel (net/xfrm): An XFRM_MSG_NEWSPDINFO request queues a per-namespace work item on the global systemCVE-2026-31516 · Linux kernel (net/xfrm)High
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2026-31656 · Linux i915 GPU kernel driverHigh
- sudo: failed setuid/setgid/setgroups before running the mailer is non-fatal, allowing privilege escalationCVE-2026-35535 · sudo (privilege drop before invoking the mailer)High
- QEMU: guest-triggered out-of-bounds write when a physical memory map returns shortCVE-2026-3842 · QEMU (cpu_physical_memory_map short-mapping handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.