
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31543 is a Linux kernel information disclosure vulnerability in the crash_dump subsystem's read_key_from_user_keying() function. When debug logging is enabled, the function logs the first 8 bytes of the dm-crypt key payload, partially exposing the encryption key to anyone with access to debug logs. The vulnerability was disclosed on April 24, 2026, and affects Linux kernel versions 6.16 through 6.18.19, 6.19 through 6.19.9, and 7.0-rc1 through 7.0-rc4. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-215 (Insertion of Sensitive Information Into Debugging Code). The read_key_from_user_keying() function in the kernel's crash_dump module includes a debug log statement that prints the first 8 bytes of the dm-crypt key payload retrieved from the user keyring. An attacker with local access and the ability to read kernel debug logs (e.g., via dmesg or /var/log/kern.log) when debug logging is active can observe these partial key bytes. The fix removes the key byte logging entirely from the function (Red Hat Bugzilla, kernel.org patch).
Successful exploitation allows a local attacker with access to kernel debug logs to recover the first 8 bytes of a dm-crypt volume encryption key, potentially weakening the confidentiality of encrypted storage volumes. While only a partial key exposure occurs, this information could assist in cryptanalytic attacks or key recovery efforts, particularly for shorter keys. The vulnerability is limited to systems where kernel debug logging is explicitly enabled and the attacker has sufficient privileges to read kernel log output (Red Hat Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, reflecting very low probability of exploitation in the near term. Exploitation requires local access and debug logging to be enabled, significantly limiting the attack surface (Red Hat Advisory).
Patches are available in Linux kernel versions 6.18.20, 6.19.10, and 7.0 (final release). The relevant upstream commits are 36f46b0e36892eba08978eef7502ff3c94ddba77, 4897bd307ba8757c31a3325ba6730961be606016, and ed8d91f469845d62d44c565a55d2ab1767969357. As an immediate workaround, disable kernel debug logging if it is not required, and restrict access to kernel logs (e.g., dmesg, /var/log/kern.log) to privileged users only. Ensure that system logs containing sensitive kernel output are protected with appropriate access controls (kernel.org patch, Red Hat Bugzilla).
The vulnerability was reported via the standard Linux kernel CVE announcement process by Greg Kroah-Hartman and tracked by Red Hat's Product Security team. No significant public researcher commentary or media coverage beyond routine vulnerability tracking has been observed. The Yocto Project security mailing list also referenced the CVE in the context of embedded Linux security updates (Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bionic
linux
bionic (esm-infra)
linux
bionic (fips-updates)
linux-fips
bionic (fips)
linux-fips
devel
linux
focal
linux
focal (esm-infra)
linux
focal (fips-updates)
linux-fips
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."