high
CISA KEV
CVE-2026-31431
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
// Description
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
// Required action
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal remediation due May 15, 2026 — past due
Advertisement
// Coverage
- CVE-2026-31431: Analyzing the Copy.Fail Linux Kernel LPE
May 12, 2026
- "Dirty Frag" Linux Kernel LPE: Unpatched Root Access Risk
May 8, 2026
- CVE-2026-31431: CISA Warns of Linux Local Privilege Escalation Exploit
May 3, 2026
- CVE-2026-31431: Linux Kernel Resource Transfer Vulnerability Actively Exploited
May 1, 2026