CVE-2026-31431: 732 bytes, no offsets, cross-distro, memory-only (no disk artifacts), extant since 2017. Discovered by AI in ~1 hour. AF_ALG's own maintainers have stated the interface has "never been used much, other than in exploits." Several major distros shipped it as a kernel builtin (=y), making the standard modprobe.d mitigation silently do nothing.
Not looking for "patch your systems" responses. Looking for honest probabilistic (or paranoid) reasoning about what a nine-year undetected window on this specific scenario actually implies for infrastructure that was exposed and is now forensically not terribly auditable.