Improper control of a resource through its lifetime in Linux kernel - CVE-2026-31431
Published: April 25, 2026 / Updated: April 30, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper memory handling within the authencesn cryptographic template in algif_aead when processing AEAD operations. A local user can trigger the vulnerable code path to execute arbitrary code on the system.