CVE.RADIO
FREN

CVE-2026-31431

Linux KernelActively Exploited (CISA KEV)CVSS 7.8KEVPatched

Actively exploited (CISA KEV) - patch before 2026-05-15

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

Actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A fixed version is available (see the table below).

Recommended action: Patch immediately: this flaw is being exploited and a fix exists. Update to the fixed version for your distribution.

CVE-2026-31431 Linux Kernel Actively Exploited (CISA KEV)

Severity metrics

CVSS 3.1 : 7.8 HIGH

Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh

Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Archlinux4.14.1-16.19.12-1fixed

Sources

Published 2026-07-04