CVE-2026-31431

high KEV
Published 2026-05-04 · Modified 2026-05-05
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.3

Description

Important: kernel-rt security update

CISA KEV

Vendor
Linux
Product
Kernel
Due date
2026-05-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-13578.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:13578

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-13577.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2453803

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2424886

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2301637

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:13577

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-13565.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2454844

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2448745

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2439852

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-19225.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2467771

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2461763

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2460538

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2436779

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-A002.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-A001.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/show_bug.cgi?id=2460538

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/; https://xint.io/blog/copy-fail-linux-distributions#the-fix-6 ; https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-31431

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-31431

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-31431.html

vendor Authored 2026-05-27

Vendor advisory: 134c704f-9b21-4f2e-91b3-4a467353bcc0 — https://xint.io/blog/copy-fail-linux-distributions#the-fix-6

vendor Authored 2026-05-27

Vendor advisory: 134c704f-9b21-4f2e-91b3-4a467353bcc0 — https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/5

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/16

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/15

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/14

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/12

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/11

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/30/10

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/29/26

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/29/25

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/29/23

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:19225

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:15978

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:13565

Exploits

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
arch archfixed6.19.12-1
suse slesaffected
debian debianbookwormfixed6.1.170-1
debian debianbullseyefixed5.10.251-3
debian debianforkyfixed6.19.12-1
debian debiansidfixed6.19.12-1
debian debiantrixiefixed6.12.85-1
linux linux-kernelaffected5.10.254
linux linux-kernel7.0affected
redhat rhel8.0affected
redhat rhel9.0affected
redhat rhel10.0affected
redhat rhel10.1affected
debian debian11.0affected
debian debian12.0affected
debian debian13.0affected
ubuntu ubuntu-affected
ubuntu ubuntu14.04affected
ubuntu ubuntu16.04affected
ubuntu ubuntu18.04affected
ubuntu ubuntu20.04affected
ubuntu ubuntu22.04affected
ubuntu ubuntu24.04affected
ubuntu ubuntu25.10affected
suse suse15.3affected
suse suse15.4affected
suse suse15.5affected
suse suse15.6affected
suse suse11affected
suse suse12affected
suse suse15affected
suse suse16.0affected
suse suse16.1affected

Application impact

VendorProductVersionsFixed
redhatopenshift_container_platform4.0
susecaas_platform4.0
suseenterprise_storage6.0
suseenterprise_storage7.0
suseenterprise_storage7.1
susemanager_proxy4.0
susemanager_proxy4.1
susemanager_proxy4.2
susemanager_proxy4.3
susemanager_retail_branch_server4.0
susemanager_retail_branch_server4.1
susemanager_retail_branch_server4.2
susemanager_retail_branch_server4.3
susemanager_server4.0
susemanager_server4.1
susemanager_server4.2
susemanager_server4.3
suseopenstack_cloud9.0
suseopenstack_cloud_crowbar9.0
aristacloudvision_agni{"startIncluding":"2024.4.0","endIncluding":"2025.2.2"}
aristacloudvision_portal{"startIncluding":"2024.2.0","endIncluding":"2026.1.0"}
aristavelocloud_edge{"startIncluding":"4.5.0","endIncluding":"6.4.1"}
aristavelocloud_gateway-
vmwarevelocloud_orchestrator-

References

CWEs

CWE-669

Verify integrity in audit chain (admin only). AS-IS.