CVE-2026-31677
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-31677 is a buffer accounting flaw in the Linux kernel's af_alg (Address Family Algorithm) crypto interface, classified as a Denial of Service vulnerability. The af_alg_get_rsgl() function fails to properly limit RX scatterlist extraction to the remaining receive buffer budget, causing a mismatch between receive-side accounting and the actual data attached to cryptographic requests. Affected Linux kernel versions span from 4.14 through pre-patch releases across multiple stable branches, including versions before 6.12.83, 6.18.24, and 6.19.14, as well as 7.0 release candidates. It was published on April 25, 2026, with a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). The af_alg_get_rsgl() function uses af_alg_readable() only as a gate before extracting data into the RX scatterlist, but does not cap each extraction to the remaining af_alg_rcvbuf(sk) budget. This allows the extracted data size to exceed the allocated receive buffer capacity. Additionally, when the skcipher subsystem cannot obtain enough RX space for at least one chunk while more data remains, it incorrectly rounds the request length down to zero rather than rejecting the recvmsg call, leading to improper cryptographic operation handling. Exploitation requires a local attacker with socket creation privileges to send specially crafted recvmsg calls via the af_alg crypto socket interface (GitHub Advisory, Feedly).

Impact

Successful exploitation allows a local user with low privileges to exhaust kernel memory or cause cryptographic operations to fail, resulting in a Denial of Service condition. The vulnerability has a High availability impact with no confidentiality or integrity impact, meaning attackers cannot leverage it for data exfiltration or unauthorized modification. The scope is limited to the affected system, with no evidence of lateral movement potential (GitHub Advisory, Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (Feedly). The EPSS score is approximately 0.015–0.018%, placing it in a very low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and low privileges, further limiting the practical attack surface.

Mitigation and workarounds

Patches are available across multiple Linux kernel stable branches. Users should upgrade to the following fixed versions: 6.12.83, 6.18.24, 6.19.14, or any 7.0 release after the rc stage (GitHub Advisory, Red Hat Advisory). Specific upstream commits addressing the issue include 07c6f6f, 4a264b2, 8eceab1, and 9bf3e6c on git.kernel.org. As a workaround, administrators can restrict unprivileged user access to af_alg crypto socket operations through security policies (e.g., SELinux, seccomp, or capability restrictions) where patching is not immediately feasible (Feedly).

Community reactions

Red Hat tracked the vulnerability via Bugzilla (bug #2461763) and issued security advisories RHSA-2026:19074 and RHSA-2026:19225 addressing the issue (Red Hat Advisory). The Yocto Project security mailing list also flagged the CVE for embedded Linux users (Yocto Security List). No significant social media commentary or notable independent researcher analysis has been identified beyond standard vulnerability tracking and distribution-level patch notifications.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management