CVSS v3.1 Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HEPSS Prediction
Documented as more likely to be exploited than 88.4% of known CVEs.
May 01, 2026
May 15, 2026
Threat Analysis
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Remediation Directive
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/
https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/
https://xint.io/blog/copy-fail-linux-distributions#the-fix-6
https://xint.io/blog/copy-fail-linux-distributions#the-fix-6
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2026-31431