Status: KEV
| Advisory ID: CVE-2026-31431
Key Details
| CVE | CVE-2026-31431 |
| Vulnerability Name | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability |
| Affected products | Linux Kernel |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-669 (Incorrect Resource Transfer Between Spheres) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-05-01. |
| Exploitation prediction (EPSS) | 3.44% probability of exploitation in the next 30 days (89% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-05-15 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | Core Infrastructure |
| Sectors | All Sectors |
What to Know
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
What to Do
Monitor Linux's web page for any future patch releases.
References
KEV Required Action