Rapidly Emerging Vulnerabilities - SCS Computing Facilities
SCS Computing Facilities is beginning a multi-phased project to migrate all SCS managed Windows computers from the SCS Windows domain, to the Andrew Windows domain.
computing.cs.cmu.eduI don’t have live tool access in this turn to pull the very latest updates, but here’s a concise summary based on the most recent publicly reported information up to now about CVE-2026-31431.
Core issue
Known impact and exploitation
Mitigations and patching
Timeline highlights (high level)
What you should do now (London-based environment)
If you’d like, I can assemble a quick checklist tailored to your environment (e.g., Ubuntu/Dedora/RHEL variants, cloud vs on-prem, containerized workloads) and, with your permission, guide you through verifying patch status and applying updates. I can also pull the most up-to-date advisories for your specific distro if you share which systems you’re running.
SCS Computing Facilities is beginning a multi-phased project to migrate all SCS managed Windows computers from the SCS Windows domain, to the Andrew Windows domain.
computing.cs.cmu.eduIn the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
www.tenable.comIn the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
cve.akaoma.comNVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. … Mailing List Patch http://www.openwall.com/lists/oss-security/2026/04/30/16CVE Mailing List Patch http://www.openwall.com/lists/oss-security/2026/04/30/17CVE … Patch
nvd.nist.govComprehensive vulnerability database for your open source projects and dependencies.
osv.devIn the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
feedly.comNVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. … Patch https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fckernel.org Patch … Patch https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c30314900287
nvd.nist.govOn this page, you can view the details of a specific CVE through an interface that correlates various data sources.
www.redhotcyber.com1. #### CVE-2026-31431 IDCVE-2026-31431 SažetakIn the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. … CVSSBase:...
cve.cert.hr