Customer requests impact of CVE on appliance

Hello,

A customer has opened a case with me to determine if the appliances, specifically the virt1, are impacted by CVE-2026-31431 for the algif_aead kernel module.

I do not see any of the recent firmware versions’ OS package updates calling out this CVE as being patched out.

I checked a lab virt1 and do not see this kernel module loaded, which suggests that at least this specific appliance is not vulnerable.

If there are any details I can take back to my client, I’d be grateful.

Thanks!

Hello Brian,

the newly released Checkmk Appliance firmware 1.7.19 contains an updated Kernel that fixes the mentioned CVE.

2 Likes

Thank you! I have passed this along to my customer.