CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability. Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
- CISA KEV-listed (remediation due 2026-05-15)
- EPSS 94.5% (99.8% percentile)
- CVSS 7.8 high
Detection rules
- Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator high
- Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator high