Siemens SIPLUS and SIMATIC Products
Apply the vendor's security update for Linux.
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Linux, fix it now.
CISA required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
US federal civilian agencies must remediate by May 15, 2026.
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: NVD patch reference
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
| Product | Vendor | Affected versions | Fixed in | Source |
|---|---|---|---|---|
| Linux | Linux | >= 4.14, < 5.10.254; >= 5.11, < 5.15.204; >= 5.16, < 6.1.170; >= 6.2, < 6.6.137; >= 6.7, < 6.12.85; >= 6.13, < 6.18.22 | 5.10.254; 5.15.204; 6.1.170; 6.6.137; 6.12.85; 6.18.22 | NVD |
| VeloCloud Orchestrator | Arista | all versions | — | NVD |
Sources: NVD = NIST National Vulnerability Database.
Developments from the last 30 days, newest first.
CVE-2026-31431 scored CVSS 7.8
Basis: NIST National Vulnerability Database
Patch released for CVE-2026-31431
An official fix is now available.
Basis: NVD patch reference
Siemens SIPLUS and SIMATIC Products
Basis: CISA Cybersecurity Advisories (government advisory)
1 earlier event is available with a subscription. See plans.
Apply the vendor's security update for Linux.