Q-SYS Statement on CVE‑2026‑31431

Author: Marius Creutznacher

A critical vulnerability was discovered in the Linux kernel's algif_aead cryptographic algorithm interface and was assigned CVE identifier CVE‑2026‑31431.

Upon disclosure of this issue the Acuity Brands Security Team performed an investigation and our analysis showed that Q-SYS OS Kernel does not include nor load the identified vulnerable modules.

Therefore, Q-SYS OS is not directly affected by CVE‑2026‑31431.

 

No Previous Articles

Next Article
Q-SYS Core Unauthenticated Privileged Operations
Q-SYS Core Unauthenticated Privileged Operations

Q-SYS Core Processors do not require an administrator to set up remote authentication during configuration,...