Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 99.9%; technical severity is CVSS 7.8.
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
Who should care
- Teams operating Amazon Linux, Cloudvision Agni, Cloudvision Portal +41 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Amazon Linux, Cloudvision Agni, Cloudvision Portal +41 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Vendor remediation
Patch and remediation links
Use the vendor source below to confirm the correct fixed version, package or mitigation for your affected product.
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-669
- Affected versions
- Amazon Amazon Linux (Version: -); Arista Cloudvision Agni (Start Including: 2024.4.0, End Including: 2025.2.2); Arista Cloudvision Portal (Start Including: 2024.2.0, End Including: 2026.1.0); Arista Netvisor Os (Version: 7.1.0); Arista Velocloud Edge (Start Including: 4.5.0, End Including: 6.4.1); Arista Velocloud Gateway (Version: -); Arista VeloCloud Orchestrator (Version: -); Canonical Ubuntu Linux (Version: 25.10)
- Published
- 22 April 2026
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 99.9%
- Signal calculated at 83
External references
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com
- Third-party advisory from access.redhat.com