LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 1, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 15, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-31431 to its Known Exploited Vulnerabilities catalog on May 1, 2026, with a federal patch deadline of May 15, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

This vulnerability, tracked as CVE-2026-31431, is an incorrect resource transfer between spheres issue in the Linux Kernel that could permit privilege escalation. It matters for IT and security teams because the Linux Kernel underpins many servers, cloud instances, and devices; successful exploitation could allow an attacker to gain elevated access on affected systems.

How it works

The weakness is classified under CWE-669. In this class of flaw, a resource intended for one security context or privilege sphere is transferred or made accessible to another without proper isolation.

An attacker who can trigger the incorrect transfer may obtain access to resources or capabilities outside their intended sphere, resulting in privilege escalation. Specific mechanics of exploitation must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The issue affects the Linux Kernel. It can be present in physical servers, virtual machines, containers, and embedded systems that rely on the kernel for core operations.

How to remediate

Apply mitigations per vendor instructions. Where the affected software is used in cloud services, follow applicable BOD 22-01 guidance.

If you can't patch immediately

Until a vendor update can be applied, reduce exposure by following the CISA required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If your data may have been exposed

Privilege-escalation vulnerabilities in core system components can lead to broader compromise. Organizations can run a free exposure scan of their email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLinux · Kernel
WeaknessCWE-669
Added to CISA KEVMay 1, 2026
Federal patch deadlineMay 15, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities