Known vulnerability record
CVE-2026-31431
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Summary
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Signals
Keep the signals separate
CVSS severityhighScore 7.8 · source Linux
EPSS probability99.9%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-05-01
Ransomware useunknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2026-04-22
- CVE modified
- 2026-08-05
- KEV date added
- 2026-05-01
- Dataset fetched
- 2026-08-21T03:55:04.925Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2026-31431 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2026-31431 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.