cbcvebase.
CVE-2026-31719
published 2026-05-01

CVE-2026-31719: In the Linux kernel, the following vulnerability has been resolved: crypto: krb5enc - fix async decrypt skipping hash verification krb5enc_dispatch_decrypt()…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.29%
21.6th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5enc - fix async decrypt skipping hash verification krb5enc_dispatch_decrypt() sets req->base.complete as the skcipher callback, which is the caller's own completion handler. When the skcipher completes asynchronously, this signals "done" to the caller without executing krb5enc_dispatch_decrypt_hash(), completely bypassing the integrity verification (hash check). Compare with the encrypt path which correctly uses krb5enc_encrypt_done as an intermediate callback to chain into the hash computation on async completion. Fix by adding krb5enc_decrypt_done as an intermediate callback that chains into krb5enc_dispatch_decrypt_hash() upon async skcipher completion, matching the encrypt path's callback pattern. Also fix EBUSY/EINPROGRESS handling throughout: remove krb5enc_request_complete() which incorrectly swallowed EINPROGRESS notifications that must be passed up to callers waiting on backlogged requests, and add missing EBUSY checks in krb5enc_encrypt_ahash_done for the dispatch_encrypt return value. Unset MAY_BACKLOG on the async completion path so the user won't see back-to-back EINPROGRESS notifications.

Affected

19 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= d1775a177f7f38156d541c8a3e3c91eaa6e69699 < 07cbb1bd424370671814a862913c99a6e144158807cbb1bd424370671814a862913c99a6e1441588
linuxlinux>= d1775a177f7f38156d541c8a3e3c91eaa6e69699 < e51f42114abbdf47f29dda43e7826be28907fcd2e51f42114abbdf47f29dda43e7826be28907fcd2
linuxlinux>= d1775a177f7f38156d541c8a3e3c91eaa6e69699 < 3bfbf5f0a99c991769ec562721285df7ab69240b3bfbf5f0a99c991769ec562721285df7ab69240b
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.15 < 6.18.256.18.25
linuxlinux_kernel>= 6.19 < 7.0.27.0.2
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-fde
ubuntulinux-gcp
ubuntulinux-hwe-7.0
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.0MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.