CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability. Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
- CISA KEV-listed (remediation due 2026-05-15)
- EPSS 99.9% (100.0% percentile)
- CVSS 7.8 high
Detection rules
- Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator high
- Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator high
Related briefings
- One bug class drove most Linux root flaws in 2026 2026-09-11
- AI helped turn an 18-year-old flaw into a container escape 2026-08-06
- New KVM bug lets a guest VM break out onto the host 2026-08-06
- Attackers weaponize most public exploits within 48 hours 2026-08-03
- CISA flags critical bugs in Rockwell and ABB industrial gear 2026-07-15