CVE-2026-31431
Linux Kernel — Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Weakness-Klassen (CWE)
CWE-669Class
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
cwe.mitre.org →CWE-1288Base
Improper Validation of Consistency within Input
The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Reanalysis2026-07-01 17:30 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.15:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.17:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.16:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.18:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:9.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.19:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.20:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.21:*:*:*:*:*:*:* → OR *cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:9.6:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.12 up to (excluding) 4.12.89 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.13 up to (excluding) 4.13.66 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.14 up to (excluding) 4.14.65 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.15 up to (excluding) 4.15.64 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.16 up to (excluding) 4.16.61 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.17 up to (excluding) 4.17.53 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.18 up to (excluding) 4.18.40 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.19 up to (excluding) 4.19.30 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.20 up to (excluding) 4.20.21 *cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* versions from (including) 4.21 up to (excluding) 4.21.14
Beschreibung
Der Linux Kernel enthält eine Schwachstelle bei der fehlerhaften Ressourcenübertragung zwischen Sicherheitsbereichen, die zu einer Rechteausweitung führen könnte.
Quelle: CISA_KEV
Betroffene Betriebssysteme
linux
amazon / amazon_linux
linux
suse / basesystem_module15
linux
debian / debian_linux11.0
linux
debian / debian_linux12.0
linux
debian / debian_linux13.0
linux
suse / development_tools_module15
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_aus8.4
linux
redhat / enterprise_linux_aus8.6
linux
redhat / enterprise_linux_eus10.0
linux
redhat / enterprise_linux_eus8.4
linux
redhat / enterprise_linux_eus9.4
linux
redhat / enterprise_linux_eus9.6
linux
redhat / enterprise_linux_tus8.6
linux
redhat / enterprise_linux_tus8.8
linux
redhat / enterprise_linux_update_services_for_sap_solutions8.6
linux
redhat / enterprise_linux_update_services_for_sap_solutions8.8
linux
redhat / enterprise_linux_update_services_for_sap_solutions9.0
linux
redhat / enterprise_linux_update_services_for_sap_solutions9.2
linux
opensuse / leap15.3
linux
opensuse / leap15.4
linux
opensuse / leap15.5
Öffentliche Exploit-Referenzen
Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.
Quellen & Referenzen
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667euvd
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130ceuvd
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875beuvd
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fceuvd
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82euvd
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8euvd
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237euvd
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5euvd
Verknüpfte Empfehlungen
- sans-atrisk2026-05-21 00:00 UTCFwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 20
- sans-atrisk2026-05-14 00:00 UTCFwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 19
- sans-newsbites-mail2026-04-29 00:00 UTCFollow-ups: Colorado Bill to Amend Right-to-Repair Postponed Indefinitely; French Authorities Investigate Suspect in Connection with ANTS Breach
- sans-newsbites-mail2026-04-29 00:00 UTCPatch and Mitigate Now: Linux Kernel Vulnerable to Privilege Escalation