Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85706.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-85706
Upstream
Published
2026-04-22T09:16:21Z
Modified
2026-08-28T17:47:35.761983388Z
Summary
CVE-2026-31431 affecting package kernel-hwe for versions less than 6.12.85.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: algif_aead - Revert to operating out-of-place

This mostly reverts commit 72548b093ee3 except for the copying of the associated data.

There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

References

Affected packages

Azure Linux:3 / kernel-hwe

Package

Name
kernel-hwe
Purl
pkg:rpm/azure-linux/kernel-hwe

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.12.85.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85706.json"