Is Security Analytics vulnerable to CVE-2026-31431?
search cancel

Is Security Analytics vulnerable to CVE-2026-31431?

book

Article ID: 439284

calendar_today

Updated On:

Products

Security Analytics

Issue/Introduction

As described in the RedHat release notes, CVE-2026-31431 discusses an issue with a 'copy fail' vulnerability in the Linux kernel.  

Environment

All versions of Security Analytics

Cause

A flaw was found in the Linux kernel's algif_aead cryptographic algorithm interface. An incorrect 'in-place operation' was introduced, where the source and destination data mappings were different. This could lead to unexpected behavior or data integrity issues during cryptographic operations, potentially impacting the reliability of encrypted communications.

Resolution

This vulnerability was introduced in Linux kernel 4.14.  Security Analytics 8.3.1 and earlier uses kernel 3.10.0 and thus is not vulnerable.
Security Analytics version 8.4.1 includes a patched kernel and is not susceptible to this vulnerability either.