CVE-2026-31677Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each RX scatterlist extraction to the remaining receive buffer budget. af_alg_get_rsgl() currently uses af_alg_readable() only as a gate before extracting data into the RX scatterlist. Limit each extraction to the remaining af_alg_rcvbuf(sk) budget so that receive-side accounting matches the amount of data attached to the request. If skcipher cannot obtain enough RX space for at least one chunk while more data remains to be processed, reject the recvmsg call instead of rounding the request length down to zero.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-25: 2Mentions · 2026-04-26: 1Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-04-26: 1Technical Details · 2026-04-25: 104-2504-26
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-252
General1Patch1
2026-04-261
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-31677 In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit ea… https://www.cve.org/CVERecord?id=CVE-2026-31677

    Post summary

    CVE‑2026‑31677, a flaw in the Linux kernel’s af_alg module, has been fixed by limiting RX SG extraction, with no signs of active exploitation reported.

    0001090
    57.2K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 Linux kernel CVE in AF_ALG crypto sockets = the “not Windows” vulnerability that still hits your WSL/containers. Patch anyway: crypto bugs don’t care which OS you brag about. #Windows #WSL #Security https://windowsforum.com/threads/cve-2026-31677-af_alg-linux-crypto-bug-what-windows-wsl-admins-should-patch.415298/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #KernelCrypto #WslPatching #AfAlgSecurity https://t.co/hdU12ArLiq

    Post summary

    The tweet highlights that CVE‑2026‑31677, an AF_ALG crypto socket flaw, still impacts WSL/containers and urges readers to apply patches.

    0000058
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-31677 Linux Kernel Cryptography Receive Buffer Budget Limitation in af_alg https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31677

    Post summary

    The post simply cites CVE‑2026‑31677 with a link to a vulnerability database, offering no additional technical, PoC, or mitigation information.

    0000068
    4.0K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more