THREAT OPS › CVEs › CVE-2026-31431
CVE-2026-31431 — Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Vulnerability details
- Affected productsKernel
- KEV remediation due2026-05-15
Related reporting
- ABB Ability Edgeniuscisa_advisories
- ABB Ability Edgeniuscisa_ics
- Linux Detection Engineering - Local Privilege Escalationelastic_security
- [NVD] CVE-2026-31431 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the sonvd
- Exploits and vulnerabilities in Q2 2026securelist
- May 2026 CVE Landscaperecordedfuture
- From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agentsdatadog_seclabs
- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa_ics
- How Cloudflare responded to the “Copy Fail” Linux vulnerabilitycloudflare_security
- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa_advisories
- 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")cert_eu
- Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wildelastic_security